GHSA-35fc-9hrj-3585
GitHub Security Advisory
Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API.
issue affects Apache Superset: from 2.0.0 before 4.1.0.
Users are recommended to upgrade to version 4.1.0, which fixes the issue.
Affected Packages
PyPI
apache-superset
Affected versions:
2.0.0
(fixed in 4.1.0)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: September 17, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.