cbcvebase.
CVE-2023-27526
published 2023-09-06

CVE-2023-27526: A non Admin authenticated user could incorrectly create resources using the import charts feature, on Apache Superset up to and including 2.1.0.

medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
A non Admin authenticated user could incorrectly create resources using the import charts feature, on Apache Superset up to and including 2.1.0.

Affected

2 ranges
VendorProductVersion rangeFixed in
apachesuperset<= 2.1.0
apache_software_foundationapache_superset<= 2.1.0