CVE-2023-49734: Apache Superset: Privilege Escalation Vulnerability
An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the charts allowing him to incorrectly have write permissions to these charts.This issue affects Apache Superset: before 2.1.2, from 3.0.0 before 3.0.2.
Users are recommended to upgrade to version 3.0.2 or 2.1.3, which fixes the issue.
Other sources
An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the charts allowing him to incorrectly have write permissions to these charts.This issue affects Apache Superset: before 2.1.3, from 3.0.0 before 3.0.2.
Users are recommended to upgrade to version 3.0.2 or 2.1.3, which fixes the issue.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49734?
CVE-2023-49734 has been classified as a critical vulnerability due to its potential impact on user permissions.
How do I fix CVE-2023-49734?
To remediate CVE-2023-49734, upgrade Apache Superset to version 2.1.3 or 3.0.2 or later.
Who is affected by CVE-2023-49734?
CVE-2023-49734 affects authenticated Gamma users of Apache Superset versions prior to 2.1.3 and between 3.0.0 and 3.0.2.
What type of permissions are incorrectly granted due to CVE-2023-49734?
CVE-2023-49734 allows unauthorized write permissions to charts created by authenticated Gamma users.
Which versions of Apache Superset should I avoid due to CVE-2023-49734?
Avoid using Apache Superset versions prior to 2.1.3 and between 3.0.0 and 3.0.2 to mitigate CVE-2023-49734.