Medium severity6.3NVD Advisory· Published Nov 27, 2023· Updated Jun 17, 2026
CVE-2023-40610
CVE-2023-40610
Description
Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database connection that allows access to both the examples schema and Apache Superset's metadata database, an attacker using a specially crafted CTE SQL statement could change data on the metadata database. This weakness could result on tampering with the authentication/authorization data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-supersetPyPI | < 2.1.2 | 2.1.2 |
Affected products
4- osv-coords2 versions
< 2.1.2+ 1 more
- (no CPE)range: < 2.1.2
- (no CPE)range: < 2.1.2
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2023/11/27/2nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-f678-j579-4xf5ghsaADVISORY
- lists.apache.org/thread/jvgxpk4dbxyqtsgtl4pdgbd520rc0rotnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-40610ghsaADVISORY
- github.com/orangecertcc/security-research/security/advisories/GHSA-f678-j579-4xf5nvdWEB
News mentions
0No linked articles in our index yet.