GHSA-v594-2c97-hx38
GitHub Security Advisory
Apache Superset vulnerable to improper data authorization
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Improper data authorization check on Jinja templated queries in Apache Superset up to and including 2.1.0 allows for an authenticated user to issue queries on database tables they may not have access to.
Affected Packages
PyPI
apache-superset
Affected versions:
0
(last affected: 2.1.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 27, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.