CVE-2023-42502
Apache Superset Open Redirect vulnerability
5.4
MEDIUM
CVSS 3.1
EPSS 0.10%
Description
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset versions before 3.0.0.
How to fix CVE-2023-42502
To remediate CVE-2023-42502, upgrade the affected package to a fixed version below.
- —upgrade to 3.0.0 or later
- —upgrade to 3.0.0 or later
Is CVE-2023-42502 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 3.0.0
- from 0, < 3.0.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |