Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

pypi apache-superset Security Advisories

Browse all Security Advisories for pypi apache-superset

Loading...
Moderate
GSA_kwCzR0hTQS0ycTZqLXZwdnItNnB2as4AA96P
Apache Superset vulnerable to improper SQL authorization
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 5.8
Published: 4 months ago
Moderate
GSA_kwCzR0hTQS1oY3I3LWNxd2MtcTVncc4AA9OR
Apache Superset server arbitrary file read
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 9.1
Published: 5 months ago
Moderate
GSA_kwCzR0hTQS0yOTlxLTNwOTYtNTg5OM4AA70V
Apache Superset Incorrect Authorization vulnerability
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 5.8
Published: 7 months ago
Moderate
GSA_kwCzR0hTQS13cjZnLTl3Y3ItY21xas4AA5le
Apache Superset: Improper data authorization when creating a new dataset
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 6.7
Published: 9 months ago
Moderate
GSA_kwCzR0hTQS0zdjlyLTg4NWotNzYyZ84AA5lb
Apache Superset: Improper authorization validation on dashboards and charts import
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 5.8
Published: 9 months ago
Moderate
GSA_kwCzR0hTQS01NDc0LWY3ZzUtMjczcc4AA5ld
Apache Superset: Improper validation of SQL statements allows for unauthorized access to data
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 6.6
Published: 9 months ago
Moderate
GSA_kwCzR0hTQS1tNmptLTN2MzgtNzZqNM4AA5la
Apache Superset: Improper Neutralization of custom SQL on embedded context
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 5.8
Published: 9 months ago
Moderate
GSA_kwCzR0hTQS1oN3I2LThxbW0taGo1cs4AA5lZ
Apache Superset: Improper error handling on alerts
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 5.8
Published: 9 months ago
Critical
GSA_kwCzR0hTQS1yd2hoLTZ4ODMtODR2Ns4AA4od
Cross-site Scripting in Apache superset
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 12.9
Published: 10 months ago
High
GSA_kwCzR0hTQS1nNDlqLWo0ODktM3hwZs4AA35g
Apache Superset incorrect write permissions vulnerability
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 10.3
Published: 11 months ago
Moderate
GSA_kwCzR0hTQS1qZnhqLXhmNjcteDcyM84AA35f
Apache Superset SQL injection vulnerability
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 8.7
Published: 11 months ago
Moderate
GSA_kwCzR0hTQS05NW1nLWpnZngtNTR2Oc4AA35k
Apache Superset uncontrolled resource consumption
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 8.7
Published: 11 months ago
High
GSA_kwCzR0hTQS1mNjc4LWo1NzktNHhmNc4AA3Zv
Apache Superset - Elevation of Privilege
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 9.8
Published: 12 months ago
Moderate
GSA_kwCzR0hTQS0zaHA3LTRxcTQtdjVjNs4AA3Zt
Apache Superset Allocation of Resources Without Limits or Throttling vulnerability
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 8.7
Published: 12 months ago
Moderate
GSA_kwCzR0hTQS1oYzc0LTl2am0tYzl4ds4AA3Zp
Apache Superset Open Redirect vulnerability
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 7.2
Published: 12 months ago
Moderate
GSA_kwCzR0hTQS1mZ3B3LTR3NjktajI1Ns4AA3Zs
Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 5.8
Published: 12 months ago
Moderate
GSA_kwCzR0hTQS12djY1LWZqZmotNDczNs4AA3Xl
Apache Superset has Incorrect Default Permissions
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 5.8
Published: 12 months ago
Moderate
GSA_kwCzR0hTQS13cThxLTk5cDUteGZyd84AA3Xf
Apache Superset Cross-site Scripting vulnerability
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 5.8
Published: 12 months ago
Moderate
GSA_kwCzR0hTQS1mbTRxLWo4ZzQtYzlqNM4AA1vN
Apache Superset Improper Input Validation vulnerability
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 8.7
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS05NWNoLXAzZ3ctMjNxZ84AA1vM
Apache Superset has incorrect authorization check
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 5.8
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS1majR4LW02Mmotd3Z3Z84AA1vL
Apache Superset Deserialization of Untrusted Data vulnerability
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 8.9
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS1jcHZ4LTIzNjUtNDY2Y84AA1un
Apache Superset may expose internal traces on REST API endpoints
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 5.8
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS00Zmc5LTV3NDYteG1yas4AA1u4
Apache Superset Server Side Request Forgery vulnerability
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 5.8
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS12NTk0LTJjOTctaHgzOM4AA1ut
Apache Superset vulnerable to improper data authorization
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 6.7
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS05cWMzLXA5anEtMngyN84AA1up
Apache Superset users may incorrectly create resources using the import charts feature
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 5.8
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS05ODMyLW1nZzQtM2dyNs4AA1um
Apache Superset has improper default REST API permission for Gamma users
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 7.2
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS1jbWpjLTUyZmctOWY3as4AA0WQ
Apache Superset vulnerable to Exposure of Sensitive Information
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 8.7
Published: over 1 year ago
Moderate
GSA_kwCzR0hTQS1meGpnLTI4Zm0tcGZ4aM4AA0WB
Apache Superset Server-Side Request Forgery vulnerability
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 8.7
Published: over 1 year ago
High
GSA_kwCzR0hTQS01Y3gyLXZxM2gteDUyY84AAy8Z
Apache superset missing check for default SECRET_KEY
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 11.9
Published: over 1 year ago
Moderate
GSA_kwCzR0hTQS03amhnLThtNzQtNmY2Z84AAy0X
Apache Superset vulnerable to Improper Authorization
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 5.8
Published: over 1 year ago
High
GSA_kwCzR0hTQS03MjIyLXIzN3gtOHEzbc4AAw_j
Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 11.8
Published: almost 2 years ago
Moderate
GSA_kwCzR0hTQS05Zjg4LXdnNXItOTQ3as4AAw_i
Apache Superset vulnerable to Cross-site Scripting
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 7.2
Published: almost 2 years ago
Moderate
GSA_kwCzR0hTQS03OXg1LWN2NzktNDlyas4AAw_k
Apache Superset is vulnerable to Cross-Site Scripting (XSS)
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 7.2
Published: almost 2 years ago
Moderate
GSA_kwCzR0hTQS1jeHZwLTNmcm0tMzg3Ns4AAw_h
Apache Superset's SQL Alchemy connector vulnerable to SQL Injection
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 7.2
Published: almost 2 years ago
Moderate
GSA_kwCzR0hTQS1mY2c0LXBtNmgtOXh4Ms4AAw_q
Apache Superset Open Redirect vulnerability
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 7.2
Published: almost 2 years ago
Moderate
GSA_kwCzR0hTQS1mcG1yLXFtZ2gtNDJ4Ms4AAw_p
Apache Superset vulnerable to Injection
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 7.2
Published: almost 2 years ago
Moderate
GSA_kwCzR0hTQS04ZjVqLW1neDktNWhtNc4AAw_n
Apache Superset has Improper Access Control
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 7.1
Published: almost 2 years ago
Moderate
GSA_kwCzR0hTQS03NDhyLTVyOHEtMjczbc4AAtJB
Apache Superset allows authenticated users to access metadata they have no permission to
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 5.8
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS13MzU4LXJqOTMtcjVxds4AArLC
Apache Superset Stored XSS on Dashboard markdown
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 7.2
Published: over 2 years ago
High
GSA_kwCzR0hTQS1jajdnLWg3cmYtaDhqOc4AArGT
Apache Superset OS Command Injection
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 11.8
Published: over 2 years ago
High
GSA_kwCzR0hTQS01ZnA4LWM0NW0tMjU2cM4AAqrR
Improper Encoding or Escaping of Output in Apache Superset
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 8.7
Published: over 2 years ago
High
GSA_kwCzR0hTQS00MnE0LTl4ZjktZjY3eM4AAqqA
Apache Superset allowed for database connections password leak for authenticated users
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 8.7
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS1mOHZjLWYyOHcteDljOc4AAqUo
Apache Superset Cross-site Scripting (XSS) vulnerability on the Explore page
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 7.2
Published: over 2 years ago
High
GSA_kwCzR0hTQS1wZzhtLTRwOGotMnA1Ns4AAqUX
Apache Superset SQL Injection when template processing is enabled
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 11.8
Published: over 2 years ago
Critical
GSA_kwCzR0hTQS13aDczLWhwY2ctdjMyas07XA
SQL injection in apache-superset
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 13.2
Published: over 2 years ago
High
GSA_kwCzR0hTQS1oaG0zLTQ4aDItNTk3ds0oGA
Insufficiently Protected Credentials in Apache Superset
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 8.7
Published: almost 3 years ago
Moderate
GSA_kwCzR0hTQS1wZndnLXJ4ZjQtOTdjM80WMg
Open Redirect in Apache Superset
Ecosystems: pypi
Packages: apache-superset, superset
Source: GitHub Advisory Database
Blast Radius: 8.2
Published: about 3 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTc3cHctYzNqMi01ZmM4
Plaintext password leak in Apache Superset
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 10.9
Published: over 3 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA1dzctcW1xNi1wbWpy
Users able to query database metadata in Apache Superset
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 7.1
Published: over 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTljMjktOWg0bS13ZzVw
Users can view database names in Apache Superset
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 7.1
Published: over 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZ4am0td3ZqOS05YzM5
Information disclosure in Apache Superset
Ecosystems: pypi
Packages: apache-superset
Source: GitHub Advisory Database
Blast Radius: 8.7
Published: over 4 years ago
Statistics
Advisories: 20,668
Packages: 9,040
Repositories: 3
Ecosystems: 12
Filter by Package
tensorflow 433 tensorflow-gpu 427 tensorflow-cpu 423 Django 100 apache-airflow 85 Plone 72 ansible 63 salt 56 apache-superset 51 nova 47 mlflow 46 django 44 rdiffweb 42 plone 41 vyper 38 moin 35 matrix-synapse 35 gradio 34 keystone 31 opencv-contrib-python 31 opencv-python 31 Pillow 31 pillow 26 glance 20 langchain 20 cobbler 18 mindsdb 18 mercurial 18 notebook 17 PaddlePaddle 16 cryptography 16 neutron 16 paddlepaddle 16 pyload-ng 16 ethyca-fides 15 calibreweb 15 OctoPrint 15 pyftpdlib 14 lollms 14 aiohttp 14 modoboa 14 vantage6 13 roundup 12 wagtail 12 urllib3 12 swift 12 zenml 12 twisted 12 trytond 11 onionshare-cli 11 waitress 11 horizon 11 opencv-python-headless 10 sentry 10 Flask-AppBuilder 10 opencv-contrib-python-headless 10 nautobot 10 zope 9 pyspark 9 cinder 9 kiwitcms 9 python-keystoneclient 9 ryu 9 numpy 8 pgadmin4 8 Zope 8 litellm 8 ipython 8 aubio 8 ckan 8 label-studio 8 trac 8 pip 7 lief 7 inventree 7 pysaml2 7 matrix-sydent 7 jupyter-server 7 scrapy 7 Products.CMFPlone 7 changedetection.io 6 ansible-core 6 Zope2 6 apache-airflow-providers-apache-hive 6 yt-dlp 6 requests 6 tuf 6 Moin 6 mage-ai 6 mailman 6 graphite-web 6 web2py 6 aim 6 tornado 6 lxml 6 oauthenticator 5 werkzeug 5 grpc 5 grpcio 5 lmdb 5 bleach 5 dtale 5 paramiko 5 saleor 5 langchain-experimental 5 python-gnupg 5 pretix 5 jupyterhub 5 feedparser 5 torchserve 5 whoogle-search 5 nltk 5 ait-core 5 Werkzeug 5 omero-web 5 Jinja2 5 awsiotsdk 4 keylime 4 Pygments 4 Scrapy 4 qutebrowser 4 Flask-Security-Too 4 indico 4 open-webui 4 indy-node 4 streamlit 4 jwcrypto 4 langchain-community 4 markdown2 4 nvflare 4 wasmtime 4 apache-iotdb 4 Keystone 4 apache-submarine 4 transformers 4 FreeTAKServer-UI 4 codechecker 4 bottle 4 esphome 4 PyPDF2 4 jupyterlab 4 pywasm3 4 langflow 4 software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk 4 reportlab 4 dbt-core 4 tripleo-heat-templates 4 barbican 4 Weblate 4 mobsf 4 httpie 4 aws-iot-device-sdk-v2 4 buildbot 4 Nova 4 Radicale 4 onnx 4 GitPython 4 ecdsa 3 torch 3 keyring 3 pyyaml 3 ansible-runner 3 openc3 3 django-tinymce 3 certifi 3 tinymce 3 llama-index-core 3 TinyMCE 3 tinymce/tinymce 3 openc3 3 docassemble.webapp 3 rsa 3 scikit-learn 3 bitlyshortener 3 python-jose 3 apache-libcloud 3 Red-DiscordBot 3 wasmtime 3 ajenti 3 ujson 3 mysql-connector-python 3 h2o 3 Twisted 3 apache-airflow-providers-apache-spark 3 SQLAlchemy 3 clearml 3 jupyter-server-proxy 3 anki 3 sanic 3 dulwich 3 octavia 3 pyarrow 3 django-cms 3 Products.PluggableAuthService 3 Kallithea 3 openvpn-monitor 3 openstack-heat 3 flask 3 protobuf 3 plone.supermodel 3