MEDIUM6.5
PYSEC-2026-1171
Apache Superset vulnerable to Exposure of Sensitive Information
Quick fix
PYSEC-2026-1171 — apache-superset: upgrade to the fixed version with the command below.
pip install --upgrade 'apache-superset>=2.1.0'Details
An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue affects Apache Superset version 1.3.0 up to 2.0.1.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/apache-superset
Introduced in:
1.3.0Fixed in: 2.1.0Fix
pip install --upgrade 'apache-superset>=2.1.0'References
- https://nvd.nist.gov/vuln/detail/CVE-2023-30776[ADVISORY]
- https://github.com/apache/superset[PACKAGE]
- https://lists.apache.org/thread/s9w9w10mt2sngk3solwnmq5k7md53tsz[WEB]
- http://www.openwall.com/lists/oss-security/2023/04/24/3[WEB]
- https://pypi.org/project/apache-superset[PACKAGE]
- https://github.com/advisories/GHSA-cmjc-52fg-9f7j[ADVISORY]