PT-2024-10308 · Apache · Apache Superset

·

CVE-2024-53948

·

Published

2024-12-09

·

Updated

2026-07-07

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Superset versions prior to 4.1.0
Description The issue is related to the generation of error messages containing analytics metadata information in Apache Superset. This can allow a remote attacker to gain unauthorized access to protected information. Users are recommended to upgrade to a version that fixes the issue.
Recommendations For versions prior to 4.1.0, upgrade to version 4.1.0 to resolve the issue. As a temporary workaround, consider restricting access to error messages that may contain sensitive analytics metadata information until the upgrade is applied.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00737
BIT-SUPERSET-2024-53948
CVE-2024-53948
GHSA-2CX9-54HP-R698
PYSEC-2026-1154

Affected Products

Apache Superset