CVE 5.3 MEDIUM

Apache Superset: Incorrect datasource authorization on REST API_CVE-2025-55675

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about datasources they do not have permission to access. By iterating through the datasource_id in the URL, an attacker can enumerate and confirm the existence and names of protected datasources, leading to sensitive information disclosure.

This issue affects Apache Superset: before 5.0.0.

Users are recommended to upgrade to version 5.0.0, which fixes the issue.

Basic Information

ID CVE-2025-55675
Source apache
Published Aug 14, 2025 at 13:18
Modified Aug 14, 2025 at 13:48

Affected Product

Vendor Apache Software Foundation
Product Apache Superset
Affected Versions Apache Software Foundation Apache Superset 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.