Skip to content
Apache SupersetGHSA-wr6g-9wcr-cmqj

Apache Superset: Improper data authorization when creating a new dataset

Medium5.0CVE-2024-24779 · Published Feb 28, 2024 · updated Jul 7, 2026

Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get access to unauthorized data. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
< 3.0.43.0.4
>= 3.1.0, < 3.1.13.1.1
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-863
Also known as
BIT-superset-2024-24779, CVE-2024-24779, PYSEC-2026-1191

More Apache Superset advisories

All Apache Superset
Advisory
Apache Superset Incorrect Authorization vulnerability
Medium4.3May 7, 2024
Apache Superset: Improper authorization validation on dashboards and charts import
Medium4.3Feb 28, 2024
Apache Superset: Improper validation of SQL statements allows for unauthorized access to data
Medium4.9Feb 28, 2024
Apache Superset: Improper Neutralization of custom SQL on embedded context
Medium4.3Feb 28, 2024
Apache Superset: Improper error handling on alerts
Medium4.3Feb 28, 2024
Cross-site Scripting in Apache superset
Critical9.6Jan 23, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.