Medium severity5.3NVD Advisory· Published Jan 16, 2023· Updated Jun 17, 2026
CVE-2022-45438
CVE-2022-45438
Description
When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-supersetPyPI | <= 1.5.2 | — |
Affected products
7- ghsa-coords2 versions
<= 1.5.2+ 1 more
- (no CPE)range: <= 1.5.2
- (no CPE)range: < 1.5.3
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-8f5j-mgx9-5hm5ghsaADVISORY
- lists.apache.org/thread/snxbkf2x9kww7s0wkmydct9nhqqn9rv9nvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-45438ghsaADVISORY
News mentions
0No linked articles in our index yet.