First published: Mon Jan 16 2023(Updated: )
Dashboard rendering does not sufficiently sanitize the content of markdown components leading to possible XSS attack vectors that can be performed by authenticated users with create dashboard permissions. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Superset | <=1.5.2 | |
Apache Superset | =2.0.0 | |
Apache Superset | =2.0.0-rc1 | |
Apache Superset | =2.0.0-rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2022-43717.
CVE-2022-43717 has a severity level of medium with a CVSS score of 5.4.
Apache Superset versions 1.5.2 and prior versions, as well as version 2.0.0 and version 2.0.0-rc1 and 2.0.0-rc2 are affected by this vulnerability.
CVE-2022-43717 allows authenticated users with create dashboard permissions to perform possible XSS attack vectors by exploiting insufficient sanitization of markdown components in dashboard rendering.
Yes, updating Apache Superset to version 1.5.3 or later for versions prior to 2.0.0, and version 2.0.0.1 or later for versions 2.0.0 and 2.0.0-rc1 and 2.0.0-rc2 resolves CVE-2022-43717.