Vulnerabilities > Apache > Superset > 0.31

DATE CVE VULNERABILITY TITLE RISK
2023-01-16 CVE-2022-43719 Cross-Site Request Forgery (CSRF) vulnerability in Apache Superset
Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery.
network
low complexity
apache CWE-352
8.8
2023-01-16 CVE-2022-43720 Unspecified vulnerability in Apache Superset
An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the toast message displayed when a user deletes that specific CSS template record. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
network
low complexity
apache
5.4
2023-01-16 CVE-2022-43721 Open Redirect vulnerability in Apache Superset
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
network
low complexity
apache CWE-601
5.4
2023-01-16 CVE-2022-45438 Exposure of Resource to Wrong Sphere vulnerability in Apache Superset
When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
network
low complexity
apache CWE-668
5.3
2021-04-27 CVE-2021-28125 Open Redirect vulnerability in Apache Superset
Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious.
network
low complexity
apache CWE-601
6.1
2021-03-05 CVE-2021-27907 Cross-site Scripting vulnerability in Apache Superset
Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information.
network
low complexity
apache CWE-79
5.4
2020-09-17 CVE-2020-13948 Unspecified vulnerability in Apache Superset
While investigating a bug report on Apache Superset, it was determined that an authenticated user could craft requests via a number of templated text fields in the product that would allow arbitrary access to Python’s `os` package in the web application process in versions < 0.37.1.
network
low complexity
apache
8.8