This issue affects Apache Superset: before 2.1.2.
Users should upgrade to version or above 2.1.2 and run `superset init` to reconstruct the Gamma role or remove `can_read` permission from the mentioned resources.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3047 | Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and annotations. This issue affects Apache Superset: before 2.1.2. Users should upgrade to version or above 2.1.2 and run `superset init` to reconstruct the Gamma role or remove `can_read` permission from the mentioned resources. |
Github GHSA |
GHSA-vv65-fjfj-4736 | Apache Superset has Incorrect Default Permissions |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 13 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache Software Foundation
Apache Software Foundation apache Superset |
|
| CPEs | cpe:2.3:a:apache_software_foundation:apache_superset:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache Software Foundation
Apache Software Foundation apache Superset |
|
| Metrics |
ssvc
|
Thu, 13 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and annotations. This issue affects Apache Superset: before 2.1.2. Users should upgrade to version or above 2.1.2 and run `superset init` to reconstruct the Gamma role or remove `can_read` permission from the mentioned resources. | Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and annotations. This issue affects Apache Superset: before 2.1.2. Users should upgrade to version or above 2.1.2 and run `superset init` to reconstruct the Gamma role or remove `can_read` permission from the mentioned resources. |
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-06-05T14:08:25.751Z
Reserved: 2023-09-11T09:03:06.448Z
Link: CVE-2023-42501
Updated: 2024-08-02T19:23:39.502Z
Status : Modified
Published: 2023-11-27T11:15:07.743
Modified: 2025-02-13T17:17:08.593
Link: CVE-2023-42501
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA