Apache SupersetGHSA-vv65-fjfj-4736
Apache Superset has Incorrect Default Permissions
Medium4.3CVE-2023-42501 · Published Nov 27, 2023 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 2.1.2 | 2.1.2 |
Details and references
Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and annotations. This issue affects Apache Superset: before 2.1.2. Users should upgrade to version or above 2.1.2 and run `superset init` to reconstruct the Gamma role or remove `can_read` permission from the mentioned resources.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-276
- Also known as
- BIT-superset-2023-42501, CVE-2023-42501, PYSEC-2026-1188
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Nov 272023 | Apache Superset Cross-site Scripting vulnerability CVE-2023-43701Medium4.3fixed in 2.1.2 | Medium4.3 | 2.1.2 |
| Nov 282023 | Apache Superset Allocation of Resources Without Limits or Throttling vulnerability CVE-2023-42504Medium6.5fixed in 3.0.0 | Medium6.5 | 3.0.0 |
| Nov 282023 | Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability CVE-2023-42505Medium4.3fixed in 3.0.0 | Medium4.3 | 3.0.0 |
| Nov 282023 | Apache Superset Open Redirect vulnerability CVE-2023-42502Medium5.4fixed in 3.0.0 | Medium5.4 | 3.0.0 |
| Nov 282023 | Apache Superset - Elevation of Privilege CVE-2023-40610High7.3fixed in 2.1.2 | High7.3 | 2.1.2 |
| Dec 192023 | Apache Superset uncontrolled resource consumption CVE-2023-46104Medium6.5fixed in 2.1.2, 3.1.0rc1 | Medium6.5 | 2.1.2, 3.1.0rc1 |