VYPR

Superset

by Apache

pypi: superset

Source repositories

CVEs (70)

  • CVE-2025-55675MedAug 14, 2025
    risk 0.42cvss 6.5epss 0.01

    Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about datasources they do not have permission to access. By iterating through the datasource_id in the URL,…

  • CVE-2025-55674MedAug 14, 2025
    risk 0.42cvss 6.5epss 0.01

    A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline block to circumvent the denylist. This allows a user with SQL Lab access to execute functions that were intended…

  • CVE-2025-48912MedMay 30, 2025
    risk 0.42cvss 6.5epss 0.01

    An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression' fields. This allowed the execution of sub-queries to evade parsing defenses ultimately granting unauthorized access to data. …

  • CVE-2024-23952MedFeb 14, 2024
    risk 0.42cvss 6.5epss 0.02

    This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.   This vulnerability…

  • CVE-2021-42250MedNov 17, 2021
    risk 0.42cvss 6.5epss 0.02

    Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs.

  • CVE-2021-41972MedNov 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way.

  • CVE-2021-27907MedMar 5, 2021
    risk 0.42cvss 5.4epss 0.86

    Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information. Abusing this functionality, a malicious user could inject javascript code executing unwanted action in the context of the…

  • CVE-2020-1932MedJan 28, 2020
    risk 0.42cvss 6.5epss 0.01

    An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented API endpoint on Apache Superset.

  • CVE-2023-40610MedNov 27, 2023
    risk 0.41cvss 6.3epss 0.01

    Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database connection that allows access to both the examples schema and Apache Superset's metadata database, an attacker using a specially…

  • CVE-2023-42504MedNov 28, 2023
    risk 0.38cvss 5.8epss 0.01

    An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports, leading to a possible denial of service. This issue affects Apache Superset: before 3.0.0

  • CVE-2021-28125MedApr 27, 2021
    risk 0.38cvss 6.1epss 0.64

    Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince…

  • CVE-2025-55672MedAug 14, 2025
    risk 0.35cvss 5.4epss 0.01

    A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and gets executed in the victim's…

  • CVE-2024-55633MedDec 12, 2024
    risk 0.35cvss 6.5epss 0.03

    Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is Incorrectly identified as a read-only query, enabling its execution. Non postgres analytics database…

  • CVE-2024-53949MedDec 9, 2024
    risk 0.35cvss 6.5epss 0.01

    Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API.  issue affects Apache Superset: from 2.0.0 before 4.1.0. Users are recommended to upgrade to version 4.1.0,…

  • CVE-2023-49736MedDec 19, 2023
    risk 0.35cvss 6.5epss 0.01

    A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Superset.This issue affects Apache Superset: before 2.1.2, from 3.0.0 before 3.0.2. Users are recommended to upgrade to version…

  • CVE-2023-46104MedDec 19, 2023
    risk 0.35cvss 6.5epss 0.02

    Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.   This vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1.

  • CVE-2022-45438MedJan 16, 2023
    risk 0.35cvss 5.3epss 0.01

    When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior versions and…

  • CVE-2022-43721MedJan 16, 2023
    risk 0.35cvss 5.4epss 0.01

    An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.

  • CVE-2022-43720MedJan 16, 2023
    risk 0.35cvss 5.4epss 0.01

    An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the toast message displayed when a user deletes that specific CSS template record. This issue affects Apache Superset version 1.5.2…

  • CVE-2022-43718MedJan 16, 2023
    risk 0.35cvss 5.4epss 0.01

    Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by authenticated users with database connection update permissions. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.