Apache Software Foundation Apache Superset vulnerabilities
61 known vulnerabilities affecting apache_software_foundation/apache_superset.
Total CVEs
61
CISA KEV
1
actively exploited
Public exploits
5
Exploited in wild
3
Severity breakdown
CRITICAL3HIGH5MEDIUM53
Vulnerabilities
Page 3 of 4
CVE-2023-43701P4MEDIUMCVSS 5.4fixed in 2.1.22023-11-27
CVE-2023-43701 [MEDIUM] CWE-79 CVE-2023-43701: Improper payload validation and an improper REST API response type, made it possible for an authenti
Improper payload validation and an improper REST API response type, made it possible for an authenticated malicious actor to store malicious code into Chart's metadata, this code could get executed if a user specifically accesses a specific deprecated API endpoint. This issue affects Apache Superset versions prior to 2.1.2.
Users are recommended to u
nvd
CVE-2021-32609P4MEDIUMCVSS 5.4≥ unspecified, ≤ 1.12021-10-18
CVE-2021-32609 [MEDIUM] CWE-79 CVE-2021-32609: Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This
Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a chart with a malicious title, injecting html (including scripts) into the page.
nvd
CVE-2025-55672P4MEDIUMCVSS 5.4fixed in 5.0.02025-08-14
CVE-2025-55672 [MEDIUM] CWE-80 CVE-2025-55672: A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. A
A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and gets executed in the victim's browser when they hover over the chart, potentially leading to session hi
nvd
CVE-2022-43718P4MEDIUMCVSS 5.4≥ 2.0.0, < 2.0.1≤ 1.5.22023-01-16
CVE-2022-43718 [MEDIUM] CWE-79 CVE-2022-43718: Upload data forms do not correctly render user input leading to possible XSS attack vectors that can
Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by authenticated users with database connection update permissions. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
nvd
CVE-2022-43717P4MEDIUMCVSS 5.4≥ 2.0.0, < 2.0.1≤ 1.5.22023-01-16
CVE-2022-43717 [MEDIUM] CWE-79 CVE-2022-43717: Dashboard rendering does not sufficiently sanitize the content of markdown components leading to pos
Dashboard rendering does not sufficiently sanitize the content of markdown components leading to possible XSS attack vectors that can be performed by authenticated users with create dashboard permissions. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
nvd
CVE-2022-43721P4MEDIUMCVSS 5.4≥ 2.0.0, < 2.0.1≤ 1.5.22023-01-16
CVE-2022-43721 [MEDIUM] CWE-601 CVE-2022-43721: An authenticated attacker with update datasets permission could change a dataset link to an untruste
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
nvd
CVE-2023-49657P4MEDIUMCVSS 5.4fixed in 3.0.32024-01-23
CVE-2023-49657 [MEDIUM] CWE-79 CVE-2023-49657: A stored cross-site scripting (XSS) vulnerability exists in Apache Superset before 3.0.3. An authent
A stored cross-site scripting (XSS) vulnerability exists in Apache Superset before 3.0.3. An authenticated attacker with create/update permissions on charts or dashboards could store a script or add a specific HTML snippet that would act as a stored XSS.
For 2.X versions, users should change their config to include:
TALISMAN_CONFIG = {
"content_sec
nvd
CVE-2023-42502P4MEDIUMCVSS 5.4fixed in 3.0.02023-11-28
CVE-2023-42502 [MEDIUM] CWE-601 CVE-2023-42502: An authenticated attacker with update datasets permission could change a dataset link to an untruste
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset versions before 3.0.0.
nvd
CVE-2024-53948P4MEDIUMCVSS 5.3fixed in 4.1.02024-12-09
CVE-2024-53948 [MEDIUM] CWE-209 CVE-2024-53948: Generation of Error Message Containing analytics metadata Information in Apache Superset. This issu
Generation of Error Message Containing analytics metadata Information in Apache Superset.
This issue affects Apache Superset: before 4.1.0.
Users are recommended to upgrade to version 4.1.0, which fixes the issue.
nvd
CVE-2024-24772P4MEDIUMCVSS 4.3fixed in 3.0.4≥ 3.1.0, < 3.1.12024-02-28
CVE-2024-24772 [MEDIUM] CWE-89 CVE-2024-24772: A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error cou
A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1.
Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.
nvd
CVE-2024-27315P4MEDIUMCVSS 4.3fixed in 3.0.4≥ 3.1.0, < 3.1.12024-02-28
CVE-2024-27315 [MEDIUM] CWE-209 CVE-2024-27315: An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to gen
An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially crafted SQL statement that triggers an error on the database. This error is not properly handled by Apache Superset and may inadvertently surface in the error log of the Alert exposing possibly sensitive data.
This issue affects Ap
nvd
CVE-2023-32672P4MEDIUMCVSS 4.3≤ 2.1.02023-09-06
CVE-2023-32672 [MEDIUM] CWE-863 CVE-2023-32672: An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. Th
An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability allows an authenticated user to query tables that they do not have proper access to within Superset. The vulnerability can be exploited by leveraging a SQL parsing vulnerability.
nvd
CVE-2024-28148P4MEDIUMCVSS 4.3fixed in 3.1.22024-05-07
CVE-2024-28148 [MEDIUM] CWE-863 CVE-2024-28148: An authenticated user could potentially access metadata for a datasource they are not authorized to
An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2.
Users are recommended to upgrade to version 3.1.2 or above, which fixes the issue.
nvd
CVE-2025-55673P4MEDIUMCVSS 4.3fixed in 4.1.32025-08-14
CVE-2025-55673 [MEDIUM] CWE-200 CVE-2025-55673: When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoin
When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, such as table names, to the low-privileged guest user.
This issue affects Apache Superset: before 4.1.3.
Users
nvd
CVE-2021-37839P4MEDIUMCVSS 4.3≥ Apache Superset, < 1.5.12022-07-06
CVE-2021-37839 [MEDIUM] CWE-273 CVE-2021-37839: Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related t
Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.
nvd
CVE-2023-42501P4MEDIUMCVSS 4.3fixed in 2.1.22023-11-27
CVE-2023-42501 [MEDIUM] CWE-276 CVE-2023-42501: Unnecessary read permissions within the Gamma role would allow authenticated users to read configure
Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and annotations.
This issue affects Apache Superset: before 2.1.2.
Users should upgrade to version or above 2.1.2 and run `superset init` to reconstruct the Gamma role or remove `can_read` permission from the mentioned resources.
nvd
CVE-2023-39264P4MEDIUMCVSS 4.3≤ 2.1.02023-09-06
CVE-2023-39264 [MEDIUM] CWE-209 CVE-2023-39264: By default, stack traces for errors were enabled, which resulted in the exposure of internal traces
By default, stack traces for errors were enabled, which resulted in the exposure of internal traces on REST API endpoints to users. This vulnerability exists in Apache Superset versions up to and including 2.1.0.
nvd
CVE-2023-27525P4MEDIUMCVSS 4.3≤ 2.0.12023-04-17
CVE-2023-27525 [MEDIUM] CWE-863 CVE-2023-27525: An authenticated user with Gamma role authorization could have access to metadata information using
An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1
nvd
CVE-2023-27523P4MEDIUMCVSS 4.3≤ 2.1.02023-09-06
CVE-2023-27523 [MEDIUM] CWE-863 CVE-2023-27523: Improper data authorization check on Jinja templated queries in Apache Superset up to and including
Improper data authorization check on Jinja templated queries in Apache Superset up to and including 2.1.0 allows for an authenticated user to issue queries on database tables they may not have access to.
nvd
CVE-2023-42505P4MEDIUMCVSS 4.3fixed in 3.0.02023-11-28
CVE-2023-42505 [MEDIUM] CWE-200 CVE-2023-42505: An authenticated user with read permissions on database connections metadata could potentially acces
An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username.
This issue affects Apache Superset before 3.0.0.
nvd