CVE-2025-55675
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-08-14

Last updated on: 2025-11-04

Assigner: Apache Software Foundation

Description
Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about datasources they do not have permission to access. By iterating through the datasource_id in the URL, an attacker can enumerate and confirm the existence and names of protected datasources, leading to sensitive information disclosure. This issue affects Apache Superset: before 5.0.0. Users are recommended to upgrade to version 5.0.0, which fixes the issue.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-08-14
Last Modified
2025-11-04
Generated
2026-05-27
AI Q&A
2025-08-14
EPSS Evaluated
2026-05-25
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
apache superset to 5.0.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an improper access control issue in Apache Superset's /explore endpoint. It allows an authenticated user to bypass authorization checks and access metadata about datasources they are not permitted to see. By changing the datasource_id parameter in the URL, an attacker can enumerate and confirm the existence and names of protected datasources, leading to disclosure of sensitive information.


How can this vulnerability impact me? :

The vulnerability can lead to sensitive information disclosure by allowing unauthorized users to discover metadata about datasources they should not access. This could expose confidential or proprietary data details, potentially aiding further attacks or data breaches.


What immediate steps should I take to mitigate this vulnerability?

Users are recommended to upgrade Apache Superset to version 5.0.0 or later, as this version fixes the improper access control vulnerability in the /explore endpoint.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart