GHSA-8f5j-mgx9-5hm5
GitHub Security Advisory
Apache Superset has Improper Access Control
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
When explicitly enabling the feature flag `DASHBOARD_CACHE` (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
Affected Packages
PyPI
apache-superset
Affected versions:
0
(last affected: 1.5.2)
PyPI
apache-superset
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 27, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.