When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
2023-01-16T11:15:10.730
2025-04-07T15:15:41.557
Modified
CVSSv3.1: 5.3 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | apache | superset | ≤ 1.5.2 | Yes |
| Application | apache | superset | 2.0.0 | Yes |
| Application | apache | superset | 2.0.0 | Yes |
| Application | apache | superset | 2.0.0 | Yes |