Apache SupersetGHSA-wr6g-9wcr-cmqj
Apache Superset: Improper data authorization when creating a new dataset
Medium5.0CVE-2024-24779 · Published Feb 28, 2024 · updated Jul 7, 2026
Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get access to unauthorized data. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 3.0.4 | 3.0.4 |
| >= 3.1.0, < 3.1.1 | 3.1.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-863
- Also known as
- BIT-superset-2024-24779, CVE-2024-24779, PYSEC-2026-1191
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 72024 | Apache Superset Incorrect Authorization vulnerability | Medium4.3 | 3.1.2 |
| Feb 282024 | Apache Superset: Improper authorization validation on dashboards and charts import | Medium4.3 | 3.0.4+1 more |
| Feb 282024 | Apache Superset: Improper validation of SQL statements allows for unauthorized access to data | Medium4.9 | 3.0.4+1 more |
| Feb 282024 | Apache Superset: Improper Neutralization of custom SQL on embedded context | Medium4.3 | 3.0.4+1 more |
| Feb 282024 | Apache Superset: Improper error handling on alerts | Medium4.3 | 3.0.4+1 more |
| Jan 232024 | Cross-site Scripting in Apache superset | Critical9.6 | 3.0.3 |