GHSA-cmjc-52fg-9f7j
GitHub Security Advisory
Apache Superset vulnerable to Exposure of Sensitive Information
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue affects Apache Superset version 1.3.0 up to 2.0.1.
Affected Packages
PyPI
apache-superset
Affected versions:
1.3.0
(fixed in 2.1.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 27, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.