CVE-2025-55675
- EPSS 0.05%
- Published 14.08.2025 13:18:53
- Last modified 18.08.2025 18:22:52
Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about datasources they do not have permission to access. By iterating through ...
CVE-2025-55674
- EPSS 0.07%
- Published 14.08.2025 13:18:10
- Last modified 18.08.2025 18:25:25
A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline block to circumvent the denylist. This allows a user with SQL Lab access to execute f...
CVE-2025-55672
- EPSS 0.05%
- Published 14.08.2025 13:17:33
- Last modified 18.08.2025 15:12:56
A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and g...
CVE-2025-55673
- EPSS 0.1%
- Published 14.08.2025 13:16:27
- Last modified 18.08.2025 18:27:31
When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, such as tab...
CVE-2025-48912
- EPSS 0.12%
- Published 30.05.2025 08:26:15
- Last modified 04.06.2025 18:29:44
An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression' fields. This allowed the execution of sub-queries to evade parsing defenses ultimately granting unau...
CVE-2025-27696
- EPSS 0.02%
- Published 13.05.2025 08:21:21
- Last modified 29.09.2025 21:49:41
Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissions. This issue affects Apache Superset: through 4.1.1. Users are recommended to upgrade t...
CVE-2024-55633
- EPSS 0.87%
- Published 12.12.2024 15:15:17
- Last modified 12.02.2025 10:15:14
Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is Incorrectly identified as a read-only query, enabling its execution. Non p...
CVE-2024-53949
- EPSS 0.46%
- Published 09.12.2024 14:15:12
- Last modified 12.02.2025 10:15:13
Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API. issue affects Apache Superset: from 2.0.0 before 4.1.0. Users are recommended to ...
CVE-2024-53948
- EPSS 0.81%
- Published 09.12.2024 14:15:12
- Last modified 11.02.2025 16:27:31
Generation of Error Message Containing analytics metadata Information in Apache Superset. This issue affects Apache Superset: before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue.
CVE-2024-53947
- EPSS 0.34%
- Published 09.12.2024 14:15:12
- Last modified 15.07.2025 16:29:47
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL authorizati...