GHSA-299q-3p96-5898
GitHub Security Advisory
Apache Superset Incorrect Authorization vulnerability
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request. This issue affects Apache Superset before 3.1.2.
Users are recommended to upgrade to version 3.1.2 or above, which fixes the issue.
Affected Packages
PyPI
apache-superset
Affected versions:
0
(fixed in 3.1.2)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 27, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.