CVE-2021-28125: Apache Superset Open Redirect
Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-28125?
CVE-2021-28125 is a vulnerability in Apache Superset up to and including version 1.0.1 that allows for the creation of a malicious external URL.
How does CVE-2021-28125 affect Apache Superset?
CVE-2021-28125 affects Apache Superset up to and including version 1.0.1.
What is the severity of CVE-2021-28125?
The severity of CVE-2021-28125 is medium.
How can a malicious user exploit CVE-2021-28125?
A malicious user can exploit CVE-2021-28125 by creating a short URL for a dashboard that could convince the user to click on it.
Are there any fixes or patches available for CVE-2021-28125?
There are currently no known fixes or patches available for CVE-2021-28125. It is recommended to keep the software up to date and avoid clicking on suspicious or unknown URLs.