{"id":"CVE-2021-37839","aliases":["GHSA-748r-5r8q-273m","BIT-superset-2021-37839","PYSEC-2026-776"],"title":"Apache Superset allows authenticated users to access metadata they have no permission to","summary":"Apache Superset allows authenticated users to access metadata they have no permission to","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","vendor":"apache-superset","product":"apache-superset","ecosystem":"pip","affected":["apache-superset < 1.5.1"],"patched":["apache-superset 1.5.1"],"published":"2022-07-07","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-748r-5r8q-273m","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-37839"},{"url":"https://github.com/apache/superset/commit/2bd89d1705347da5446902a3f65eb8d0a6353503"},{"url":"https://github.com/apache/superset"},{"url":"https://lists.apache.org/thread/pwqyxxmn5gh7cnw3qsp66v0lt4xojt82"}],"tags":["osv","pip"],"epss":0.01371,"epssPercentile":0.70761,"ingestedAt":"2026-07-08T18:25:46.758Z","slug":"CVE-2021-37839","body":"## Overview\n\nApache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.\n\n## Affected packages\n\n- `apache-superset < 1.5.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `apache-superset 1.5.1`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}