← Back to CVE List

CVE-2023-42501

Published: 2023-11-27T11:15Z
Last Modified: 2025-02-13T17:17Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and annotations. This issue affects Apache Superset: before 2.1.2. Users should upgrade to version or above 2.1.2 and run `superset init` to reconstruct the Gamma role or remove `can_read` permission from the mentioned resources. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt