Skip to content
Apache SupersetGHSA-hc74-9vjm-c9xv

Apache Superset Open Redirect vulnerability

Medium5.4CVE-2023-42502 · Published Nov 28, 2023 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
< 3.0.03.0.0
Details and references

An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset versions before 3.0.0.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-601
Also known as
BIT-superset-2023-42502, CVE-2023-42502, PYSEC-2026-1182

More Apache Superset advisories

All Apache Superset
DateAdvisory
Nov 272023Apache Superset has Incorrect Default Permissions
CVE-2023-42501Medium4.3fixed in 2.1.2
Nov 272023Apache Superset Cross-site Scripting vulnerability
CVE-2023-43701Medium4.3fixed in 2.1.2
Nov 282023Apache Superset Allocation of Resources Without Limits or Throttling vulnerability
CVE-2023-42504Medium6.5fixed in 3.0.0
Nov 282023Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2023-42505Medium4.3fixed in 3.0.0
Nov 282023Apache Superset - Elevation of Privilege
CVE-2023-40610High7.3fixed in 2.1.2
Dec 192023Apache Superset uncontrolled resource consumption
CVE-2023-46104Medium6.5fixed in 2.1.2, 3.1.0rc1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.