Apache Superset vulnerabilities
68 known vulnerabilities affecting apache/superset.
Total CVEs
68
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
3
Severity breakdown
CRITICAL5HIGH7MEDIUM56
Vulnerabilities
Page 4 of 4
CVE-2025-55673P4MEDIUMCVSS 4.3fixed in 4.1.32025-08-14
CVE-2025-55673 [MEDIUM] CWE-200 CVE-2025-55673: When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoin
When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, such as table names, to the low-privileged guest user.
This issue affects Apache Superset: before 4.1.3.
Users
nvd
CVE-2021-37839P4MEDIUMCVSS 4.3≤ 1.5.12022-07-06
CVE-2021-37839 [MEDIUM] CWE-273 CVE-2021-37839: Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related t
Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.
nvd
CVE-2023-42501P4MEDIUMCVSS 4.3fixed in 2.1.12023-11-27
CVE-2023-42501 [MEDIUM] CWE-276 CVE-2023-42501: Unnecessary read permissions within the Gamma role would allow authenticated users to read configure
Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and annotations.
This issue affects Apache Superset: before 2.1.2.
Users should upgrade to version or above 2.1.2 and run `superset init` to reconstruct the Gamma role or remove `can_read` permission from the mentioned resources.
nvd
CVE-2023-39264P4MEDIUMCVSS 4.3≤ 2.1.02023-09-06
CVE-2023-39264 [MEDIUM] CWE-209 CVE-2023-39264: By default, stack traces for errors were enabled, which resulted in the exposure of internal traces
By default, stack traces for errors were enabled, which resulted in the exposure of internal traces on REST API endpoints to users. This vulnerability exists in Apache Superset versions up to and including 2.1.0.
nvd
CVE-2023-27525P4MEDIUMCVSS 4.3≤ 2.0.12023-04-17
CVE-2023-27525 [MEDIUM] CWE-863 CVE-2023-27525: An authenticated user with Gamma role authorization could have access to metadata information using
An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1
nvd
CVE-2023-27523P4MEDIUMCVSS 4.3≤ 2.1.02023-09-06
CVE-2023-27523 [MEDIUM] CWE-863 CVE-2023-27523: Improper data authorization check on Jinja templated queries in Apache Superset up to and including
Improper data authorization check on Jinja templated queries in Apache Superset up to and including 2.1.0 allows for an authenticated user to issue queries on database tables they may not have access to.
nvd
CVE-2023-42505P4MEDIUMCVSS 4.3fixed in 3.0.02023-11-28
CVE-2023-42505 [MEDIUM] CWE-200 CVE-2023-42505: An authenticated user with read permissions on database connections metadata could potentially acces
An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username.
This issue affects Apache Superset before 3.0.0.
nvd
CVE-2023-27526P4MEDIUMCVSS 4.3≤ 2.1.02023-09-06
CVE-2023-27526 [MEDIUM] CWE-863 CVE-2023-27526: A non Admin authenticated user could incorrectly create resources using the import charts feature, o
A non Admin authenticated user could incorrectly create resources using the import charts feature, on Apache Superset up to and including 2.1.0.
nvd
← Previous4 / 4