Loading HuntDB...

GHSA-fgpw-4w69-j256

GitHub Security Advisory

Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username.

This issue affects Apache Superset before 3.0.0.

Affected Packages

PyPI apache-superset
Affected versions: 0 (fixed in 3.0.0)

Related CVEs

Key Information

GHSA ID
GHSA-fgpw-4w69-j256
Published
November 28, 2023 6:30 PM
Last Modified
February 13, 2025 7:25 PM
CVSS Score
5.0 /10
Primary Ecosystem
PyPI
Primary Package
apache-superset
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.