Skip to content
Apache SupersetGHSA-jfxj-xf67-x723

Apache Superset SQL injection vulnerability

Medium6.5CVE-2023-49736 · Published Dec 19, 2023 · updated Jul 7, 2026

A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Superset.This issue affects Apache Superset: before 2.1.3, from 3.0.0 before 3.0.2. Users are recommended to upgrade to version 2.1.3 or 3.0.2, which fixes the issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
< 2.1.32.1.3
>= 3.0.0, < 3.0.23.0.2
Details and references

More Apache Superset advisories

All Apache Superset
Advisory
Apache Superset uncontrolled resource consumption
Medium6.5Dec 19, 2023
Apache Superset incorrect write permissions vulnerability
High7.7Dec 19, 2023
Apache Superset - Elevation of Privilege
High7.3Nov 28, 2023
Apache Superset Allocation of Resources Without Limits or Throttling vulnerability
Medium6.5Nov 28, 2023
Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Medium4.3Nov 28, 2023
Apache Superset Open Redirect vulnerability
Medium5.4Nov 28, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.