CVE-2023-49734
Wolfi vulnerability analysis and mitigation

Overview

A privilege escalation vulnerability was discovered in Apache Superset, identified as CVE-2023-49734. The vulnerability affects Apache Superset versions before 2.1.2 and from 3.0.0 before 3.0.2. The issue was discovered by Jordan Velich and publicly disclosed on December 19, 2023 (Apache Advisory, Security Online).

Technical details

The vulnerability allows an authenticated Gamma user to gain unauthorized write permissions to charts. When a Gamma user creates a dashboard and adds charts to it, they automatically become one of the owners of the charts, resulting in incorrect authorization permissions. The vulnerability has been assigned a CVSS v3.1 base score of 7.7 (High) by Apache Software Foundation with a vector string of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N. The vulnerability is classified as CWE-863 (Incorrect Authorization) (NVD).

Impact

The vulnerability enables privilege escalation where lower-privileged users can gain undue control over chart permissions, potentially disrupting data integrity within Apache Superset installations. This security gap could lead to unauthorized modifications of charts and dashboards (Security Online).

Mitigation and workarounds

Users are recommended to upgrade to Apache Superset version 3.0.2 or 2.1.3, which contain fixes for this vulnerability. These versions have been released specifically to address this security issue (Apache Advisory).

Additional resources


SourceThis report was generated using AI

Related Wolfi vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-15514HIGH8.7
  • WolfiWolfi
  • cpe:2.3:a:ollama:ollama
NoNoJan 12, 2026
CVE-2026-22801MEDIUM6.8
  • OpenJDK JDKOpenJDK JDK
  • libpng1.6
NoYesJan 12, 2026
CVE-2026-22695MEDIUM6.1
  • OpenJDK JDKOpenJDK JDK
  • mingw32-libpng
NoYesJan 12, 2026
CVE-2026-22772MEDIUM5.8
  • WolfiWolfi
  • slsa-verifier
NoYesJan 12, 2026
CVE-2026-22784LOW2.3
  • WolfiWolfi
  • lychee
NoYesJan 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management