Skip to content
Apache SupersetGHSA-v594-2c97-hx38

Apache Superset vulnerable to improper data authorization

Medium5.0CVE-2023-27523 · Published Sep 6, 2023 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
<= 2.1.0No fix yet
Details and references

Improper data authorization check on Jinja templated queries in Apache Superset up to and including 2.1.0 allows for an authenticated user to issue queries on database tables they may not have access to.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-863
Also known as
BIT-superset-2023-27523, CVE-2023-27523, PYSEC-2026-1187

More Apache Superset advisories

All Apache Superset
DateAdvisory
Sep 62023Apache Superset Server Side Request Forgery vulnerability
CVE-2023-36388Medium4.3no fix yet
Sep 62023Apache Superset has improper default REST API permission for Gamma users
CVE-2023-36387Medium5.4no fix yet
Sep 62023Apache Superset users may incorrectly create resources using the import charts feature
CVE-2023-27526Medium4.3no fix yet
Sep 62023Apache Superset may expose internal traces on REST API endpoints
CVE-2023-39264Medium4.3no fix yet
Sep 62023Apache Superset has incorrect authorization check
CVE-2023-32672Medium4.3no fix yet
Sep 62023Apache Superset Deserialization of Untrusted Data vulnerability
CVE-2023-37941Medium6.6fixed in 2.1.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.