boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2023-27524

Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  C  H  H  L    8.9   .9740   99.9   YES
AFFECTED
  Product          Versions     Fixed
  Apache Superset  unspecified  —
TIMELINE
  Mar 2   Reserved by apache
  Apr 24  Published (CNA: apache)
  Jan 8   Added to CISA KEV, remediation due 2024-01-29
CWE-1188 · CNA: apache · CVSS v3.1 · 5 references · KEV due January 29, 2024

Description

Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config. All superset installations should always set a unique secure random SECRET_KEY. Your SECRET_KEY is used to securely sign all session cookies and encrypting sensitive information on the database. Add a strong SECRET_KEY to your `superset_config.py` file like: SECRET_KEY = <YOUR_OWN_RANDOM_GENERATED_SECRET_KEY> Alternatively you can set it with `SUPERSET_SECRET_KEY` environment variable.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
March 2, 2023ReservedReserved by apache
April 24, 2023PublishedPublished (CNA: apache)
January 8, 2024KEV ADDEDAdded to CISA KEV, remediation due 2024-01-29

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
Apache Software FoundationApache Superset———

Weaknesses

CWE-1188

References (5)

Related

Authoritative record: CVE-2023-27524 at cve.org

Vendors: apache

Weaknesses: CWE-1188

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-27524 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.