Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2023-27524
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H N N C H H L 8.9 .9740 99.9 YES
AFFECTED
Product Versions Fixed
Apache Superset unspecified —
TIMELINE
Mar 2 Reserved by apache
Apr 24 Published (CNA: apache)
Jan 8 Added to CISA KEV, remediation due 2024-01-29
Description
Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config.
All superset installations should always set a unique secure random SECRET_KEY. Your SECRET_KEY is used to securely sign all session cookies and encrypting sensitive information on the database.
Add a strong SECRET_KEY to your `superset_config.py` file like:
SECRET_KEY = <YOUR_OWN_RANDOM_GENERATED_SECRET_KEY>
Alternatively you can set it with `SUPERSET_SECRET_KEY` environment variable.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| March 2, 2023 | Reserved | Reserved by apache |
| April 24, 2023 | Published | Published (CNA: apache) |
| January 8, 2024 | KEV ADDED | Added to CISA KEV, remediation due 2024-01-29 |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Apache Software Foundation | Apache Superset | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-27524 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.