Apache SupersetGHSA-wq8q-99p5-xfrw
Apache Superset Cross-site Scripting vulnerability
Medium4.3CVE-2023-43701 · Published Nov 27, 2023 · updated Jul 7, 2026
Improper payload validation and an improper REST API response type, made it possible for an authenticated malicious actor to store malicious code into Chart's metadata, this code could get executed if a user specifically accesses a specific deprecated API endpoint. This issue affects Apache Superset versions prior to 2.1.2. Users are recommended to upgrade to version 2.1.2, which fixes this issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 2.1.2 | 2.1.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-79
- Also known as
- BIT-superset-2023-43701, CVE-2023-43701, PYSEC-2026-1190
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 192023 | Apache Superset SQL injection vulnerability | Medium6.5 | 2.1.3+1 more |
| Nov 282023 | Apache Superset - Elevation of Privilege | High7.3 | 2.1.2 |
| Nov 282023 | Apache Superset Open Redirect vulnerability | Medium5.4 | 3.0.0 |
| Nov 282023 | Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability | Medium4.3 | 3.0.0 |
| Nov 282023 | Apache Superset Allocation of Resources Without Limits or Throttling vulnerability | Medium6.5 | 3.0.0 |
| Nov 272023 | Apache Superset has Incorrect Default Permissions | Medium4.3 | 2.1.2 |