GHSA-4fg9-5w46-xmrj
GitHub Security Advisory
Apache Superset Server Side Request Forgery vulnerability
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possible SSRF.
Affected Packages
PyPI
apache-superset
Affected versions:
0
(last affected: 2.1.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 27, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.