CVE-2023-27526: Apache Superset: Improper Authorization check on import charts
A non Admin authenticated user could incorrectly create resources using the import charts feature, on Apache Superset up to and including 2.1.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27526?
The severity of CVE-2023-27526 is medium with a severity value of 4.3.
How can Apache Superset up to and including version 2.1.0 be affected by CVE-2023-27526?
Apache Superset up to and including version 2.1.0 can be affected by CVE-2023-27526 through a non Admin authenticated user incorrectly creating resources using the import charts feature.
How can I fix the vulnerability CVE-2023-27526?
To fix the vulnerability CVE-2023-27526, update Apache Superset to a version higher than 2.1.0.
Where can I find more information about CVE-2023-27526?
You can find more information about CVE-2023-27526 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-27526), [Apache Mailing List](https://lists.apache.org/thread/ndww89yl2jd98lvn23n9cj722lfdg8dv), [GitHub Advisory](https://github.com/advisories/GHSA-9qc3-p9jq-2x27).
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-27526?
The Common Weakness Enumeration (CWE) ID for CVE-2023-27526 is 863.