Moderate severityNVD Advisory· Published Sep 6, 2023· Updated Sep 26, 2024
Apache Superset: Improper Authorization check on import charts
CVE-2023-27526
Description
A non Admin authenticated user could incorrectly create resources using the import charts feature, on Apache Superset up to and including 2.1.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-supersetPyPI | <= 2.1.0 | — |
Affected products
3- osv-coords2 versions
< 2.1.1+ 1 more
- (no CPE)range: < 2.1.1
- (no CPE)range: <= 2.1.0
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-9qc3-p9jq-2x27ghsaADVISORY
- lists.apache.org/thread/ndww89yl2jd98lvn23n9cj722lfdg8dvghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-27526ghsaADVISORY
News mentions
0No linked articles in our index yet.