Skip to content
Apache SupersetGHSA-m6jm-3v38-76j4

Apache Superset: Improper Neutralization of custom SQL on embedded context

Medium4.3CVE-2024-24772 · Published Feb 28, 2024 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
< 3.0.43.0.4
>= 3.1.0, < 3.1.13.1.1
Details and references

A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20, CWE-89
Also known as
BIT-superset-2024-24772, CVE-2024-24772, PYSEC-2026-1185

More Apache Superset advisories

All Apache Superset
DateAdvisory
Feb 282024Apache Superset: Improper error handling on alerts
CVE-2024-27315Medium4.3fixed in 3.0.4, 3.1.1
Feb 282024Apache Superset: Improper validation of SQL statements allows for unauthorized access to data
CVE-2024-24773Medium4.9fixed in 3.0.4, 3.1.1
Feb 282024Apache Superset: Improper authorization validation on dashboards and charts import
CVE-2024-26016Medium4.3fixed in 3.0.4, 3.1.1
Feb 282024Apache Superset: Improper data authorization when creating a new dataset
CVE-2024-24779Medium5.0fixed in 3.0.4, 3.1.1
Jan 232024Cross-site Scripting in Apache superset
CVE-2023-49657Critical9.6fixed in 3.0.3
May 72024Apache Superset Incorrect Authorization vulnerability
CVE-2024-28148Medium4.3fixed in 3.1.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.