Apache SupersetGHSA-h7r6-8qmm-hj5r
Apache Superset: Improper error handling on alerts
Medium4.3CVE-2024-27315 · Published Feb 28, 2024 · updated Jul 7, 2026
An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially crafted SQL statement that triggers an error on the database. This error is not properly handled by Apache Superset and may inadvertently surface in the error log of the Alert exposing possibly sensitive data. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 3.0.4 | 3.0.4 |
| >= 3.1.0, < 3.1.1 | 3.1.1 |
Details and references
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 72024 | Apache Superset Incorrect Authorization vulnerability | Medium4.3 | 3.1.2 |
| Feb 282024 | Apache Superset: Improper authorization validation on dashboards and charts import | Medium4.3 | 3.0.4+1 more |
| Feb 282024 | Apache Superset: Improper data authorization when creating a new dataset | Medium5.0 | 3.0.4+1 more |
| Feb 282024 | Apache Superset: Improper validation of SQL statements allows for unauthorized access to data | Medium4.9 | 3.0.4+1 more |
| Feb 282024 | Apache Superset: Improper Neutralization of custom SQL on embedded context | Medium4.3 | 3.0.4+1 more |
| Jan 232024 | Cross-site Scripting in Apache superset | Critical9.6 | 3.0.3 |