CVE-2023-27523
Improper data authorization check on Jinja templated queries in Apache Superset up to and including 2.1.0 allows for an authenticated user to issue queries on database tables they may not have access to.
- Affected products
- Apache Superset
- Apache Superset
- ≤ 2.1.0
- Fix
- Available
- CVSS 3.1
- 5.0 MEDIUM
- EPSS
- 0.7% (52th percentile)
- Weakness
- CWE-863
- NVD status
- Modified
- Published
- 2023-09-06
CVE-2023-27523 at NVD
No indexed exploits for CVE-2023-27523 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-27523 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.