---
id: CVE-2021-37839
aliases:
  - GHSA-748r-5r8q-273m
  - BIT-superset-2021-37839
  - PYSEC-2026-776
title: >-
  Apache Superset allows authenticated users to access metadata they have no
  permission to
summary: >-
  Apache Superset allows authenticated users to access metadata they have no
  permission to
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
vendor: apache-superset
product: apache-superset
ecosystem: pip
affected:
  - apache-superset < 1.5.1
patched:
  - apache-superset 1.5.1
published: '2022-07-07'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-748r-5r8q-273m'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-37839'
  - url: >-
      https://github.com/apache/superset/commit/2bd89d1705347da5446902a3f65eb8d0a6353503
  - url: 'https://github.com/apache/superset'
  - url: 'https://lists.apache.org/thread/pwqyxxmn5gh7cnw3qsp66v0lt4xojt82'
tags:
  - osv
  - pip
epss: 0.01371
epssPercentile: 0.70776
ingestedAt: '2026-07-08T18:25:46.758Z'
---

## Overview

Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.

## Affected packages

- `apache-superset < 1.5.1`

## Remediation

Upgrade to a patched release:

- `apache-superset 1.5.1`
