CVE-2024-24772: Apache Superset

Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.

A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.

Affected products

  • Apache Superset: before 3.0.4 (fixed in 3.0.4); from 3.1.0, before 3.1.1 (fixed in 3.1.1)

Published 2024-02-28. Last modified 2026-06-17.