CVE-2023-30776: Apache Superset

Medium severity, CVSS 6.5. EPSS: 2.1% chance of exploitation in the next 30 days.

An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue affects Apache Superset version 1.3.0 up to 2.0.1.

Affected products

  • Apache Superset: from 1.3.0, up to and including 2.0.1

Published 2023-04-24. Last modified 2026-06-17.