MEDIUM5.4
PYSEC-2026-1168
Apache Superset has improper default REST API permission for Gamma users
Details
An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database connections.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/apache-superset
Introduced in:
0No fixed version published yet for apache-superset (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-36387[ADVISORY]
- https://github.com/apache/superset/pull/24185[WEB]
- https://github.com/apache/superset[PACKAGE]
- https://lists.apache.org/thread/tt6s6hm8nv6s11z8bfsk3r3d9ov0ogw3[WEB]
- https://pypi.org/project/apache-superset[PACKAGE]
- https://github.com/advisories/GHSA-9832-mgg4-3gr6[ADVISORY]