First published: Tue Apr 27 2021(Updated: )
Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Superset | <=1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28125 is a vulnerability in Apache Superset up to and including version 1.0.1 that allows for the creation of a malicious external URL.
CVE-2021-28125 affects Apache Superset up to and including version 1.0.1.
The severity of CVE-2021-28125 is medium.
A malicious user can exploit CVE-2021-28125 by creating a short URL for a dashboard that could convince the user to click on it.
There are currently no known fixes or patches available for CVE-2021-28125. It is recommended to keep the software up to date and avoid clicking on suspicious or unknown URLs.