CVE-2022-43721
Apache Superset Open Redirect vulnerability
5.4
MEDIUM
CVSS 3.1
EPSS 0.65%
Description
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
How to fix CVE-2022-43721
To remediate CVE-2022-43721, upgrade the affected package to a fixed version below.
- —upgrade to 1.5.3 or later
- —no fix listed
Is CVE-2022-43721 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.5.3, >= 2.0.0, < 2.0.1
- from 0, <= 1.5.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |