Vulnerability CVE-2024-23952


Published: 2024-02-14

Description:
This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset.

Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.  
This vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1.

Type:

CWE-400

(Uncontrolled Resource Consumption ('Resource Exhaustion'))

 References:
https://lists.apache.org/thread/zc58zvm4414molqn2m4d4vkrbrsxdksx

Copyright 2026, cxsecurity.com

 

Back to Top