Apache SupersetGHSA-v594-2c97-hx38
Apache Superset vulnerable to improper data authorization
Medium5.0CVE-2023-27523 · Published Sep 6, 2023 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | <= 2.1.0 | No fix yet |
Details and references
Improper data authorization check on Jinja templated queries in Apache Superset up to and including 2.1.0 allows for an authenticated user to issue queries on database tables they may not have access to.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-863
- Also known as
- BIT-superset-2023-27523, CVE-2023-27523, PYSEC-2026-1187
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 62023 | Apache Superset Server Side Request Forgery vulnerability CVE-2023-36388Medium4.3no fix yet | Medium4.3 | No fix yet |
| Sep 62023 | Apache Superset has improper default REST API permission for Gamma users CVE-2023-36387Medium5.4no fix yet | Medium5.4 | No fix yet |
| Sep 62023 | Apache Superset users may incorrectly create resources using the import charts feature CVE-2023-27526Medium4.3no fix yet | Medium4.3 | No fix yet |
| Sep 62023 | Apache Superset may expose internal traces on REST API endpoints CVE-2023-39264Medium4.3no fix yet | Medium4.3 | No fix yet |
| Sep 62023 | Apache Superset has incorrect authorization check CVE-2023-32672Medium4.3no fix yet | Medium4.3 | No fix yet |
| Sep 62023 | Apache Superset Deserialization of Untrusted Data vulnerability CVE-2023-37941Medium6.6fixed in 2.1.1 | Medium6.6 | 2.1.1 |