VYPR

Superset

by Apache

pypi: superset

Source repositories

CVEs (70)

  • CVE-2023-27524HigKEVApr 24, 2023
    risk 0.74cvss 8.9epss 0.97

    Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not…

  • CVE-2022-27479CriApr 13, 2022
    risk 0.64cvss 9.8epss 0.03

    Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.

  • CVE-2018-8021CriNov 7, 2018
    risk 0.64cvss 9.8epss 0.53

    Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation.

  • CVE-2023-49657CriJan 23, 2024
    risk 0.62cvss 9.6epss 0.01

    A stored cross-site scripting (XSS) vulnerability exists in Apache Superset before 3.0.3. An authenticated attacker with create/update permissions on charts or dashboards could store a script or add a specific HTML snippet that would act as a stored XSS. For 2.X versions,…

  • CVE-2024-53947CriDec 9, 2024
    risk 0.57cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL authorization. This issue is a follow-up…

  • CVE-2022-43719HigJan 16, 2023
    risk 0.57cvss 8.8epss 0.01

    Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.

  • CVE-2021-41971HigOct 18, 2021
    risk 0.57cvss 8.8epss 0.02

    Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malicious authenticated user sends an http request with a custom URL.

  • CVE-2020-13948HigSep 17, 2020
    risk 0.57cvss 8.8epss 0.03

    While investigating a bug report on Apache Superset, it was determined that an authenticated user could craft requests via a number of templated text fields in the product that would allow arbitrary access to Python’s `os` package in the web application process in versions <…

  • CVE-2020-13952HigSep 30, 2020
    risk 0.53cvss 8.1epss 0.02

    In the course of work on the open source project it was discovered that authenticated users running queries against Hive and Presto database engines could access information via a number of templated fields including the contents of query description metadata database, the…

  • CVE-2025-27696HigMay 13, 2025
    risk 0.50cvss 8.8epss 0.01

    Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissions. This issue affects Apache Superset: through 4.1.1. Users are recommended to upgrade to version 4.1.2 or above,…

  • CVE-2023-37941MedSep 6, 2023
    risk 0.48cvss 6.6epss 0.29

    If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal' component that is typically only…

  • CVE-2024-34693MedJun 20, 2024
    risk 0.44cvss 6.8epss 0.02

    Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql client on the web server are set to allow for local infile,…

  • CVE-2023-49734HigDec 19, 2023
    risk 0.43cvss 7.7epss 0.01

    An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the charts allowing him to incorrectly have write permissions to these charts.This issue affects Apache Superset: before 2.1.2, from…

  • CVE-2021-44451MedFeb 1, 2022
    risk 0.43cvss 6.5epss 0.08

    Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could be accessed in a non-trivial way. Users should upgrade to Apache Superset 1.4.0 or higher.

  • CVE-2026-23985MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The vulnerability is located in the sql_parse.py component, specifically within the SQL_REGEX used for parsing SQL statements in the sqlparse library integration.…

  • CVE-2026-23984MedFeb 24, 2026
    risk 0.42cvss 6.5epss 0.00

    An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only verification check when using a PostgreSQL database connection. While the system effectively blocks standard Data Manipulation…

  • CVE-2026-23983MedFeb 24, 2026
    risk 0.42cvss 6.5epss 0.00

    A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoint (disabled by default) allows users to retrieve a list of objects associated with a specific tag. When these associated objects…

  • CVE-2026-23982MedFeb 24, 2026
    risk 0.42cvss 6.5epss 0.00

    An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a dataset, Superset enforces permission checks to prevent users from querying unauthorized data. However, an authenticated attacker…

  • CVE-2026-23980MedFeb 24, 2026
    risk 0.42cvss 6.5epss 0.01

    Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where parameters. This issue affects Apache Superset:…

  • CVE-2026-23969MedFeb 24, 2026
    risk 0.42cvss 6.5epss 0.01

    Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within SQL Lab and charts. While this feature included restrictions for engines like PostgreSQL, a vulnerability was reported where the…

Page 1 of 4