CVE-2021-42250: Possible log injection
Published Nov 17, 2021
·Updated
Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs.
Affected Software
2 affected componentsFixes available
Apache Superset<1.3.2
pip/apache-superset<=1.3.1
1.3.2
Event History
Nov 17, 2021
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
DescriptionWeakness
May 24, 2022
Advisory Published
via GitHub·07:20 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-42250?
The severity of CVE-2021-42250 is medium.
2
How does CVE-2021-42250 affect Apache Superset?
CVE-2021-42250 affects Apache Superset versions up to and excluding 1.3.2.
3
What is the impact of CVE-2021-42250?
CVE-2021-42250 allows an authenticated user to forge log entries or inject malicious content into logs.
4
Is there a fix for CVE-2021-42250?
To fix CVE-2021-42250, upgrade to Apache Superset version 1.3.2 or higher.
5
Where can I find more information about CVE-2021-42250?
You can find more information about CVE-2021-42250 at the following references: [CVE-2021-42250 - Openwall](http://www.openwall.com/lists/oss-security/2021/11/17/2), [CVE-2021-42250 - Apache mailing list](https://lists.apache.org/thread/53lkszw6d3tybp5t99nvgcj538b9trw9).