Skip to content
Apache SupersetGHSA-g49j-j489-3xpf

Apache Superset incorrect write permissions vulnerability

High7.7CVE-2023-49734 · Published Dec 19, 2023 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
< 2.1.32.1.3
>= 3.0.0, < 3.0.23.0.2
Details and references

An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the charts allowing him to incorrectly have write permissions to these charts.This issue affects Apache Superset: before 2.1.3, from 3.0.0 before 3.0.2. Users are recommended to upgrade to version 3.0.2 or 2.1.3, which fixes the issue.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-863
Also known as
BIT-superset-2023-49734, CVE-2023-49734, PYSEC-2026-1180

More Apache Superset advisories

All Apache Superset
DateAdvisory
Dec 192023Apache Superset uncontrolled resource consumption
CVE-2023-46104Medium6.5fixed in 2.1.2, 3.1.0rc1
Dec 192023Apache Superset SQL injection vulnerability
CVE-2023-49736Medium6.5fixed in 2.1.3, 3.0.2
Nov 282023Apache Superset - Elevation of Privilege
CVE-2023-40610High7.3fixed in 2.1.2
Nov 282023Apache Superset Allocation of Resources Without Limits or Throttling vulnerability
CVE-2023-42504Medium6.5fixed in 3.0.0
Nov 282023Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2023-42505Medium4.3fixed in 3.0.0
Nov 282023Apache Superset Open Redirect vulnerability
CVE-2023-42502Medium5.4fixed in 3.0.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.