CVE-2022-43718: Apache Superset: Cross-Site Scripting vulnerability on upload forms
Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by authenticated users with database connection update permissions. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43718?
The severity of CVE-2022-43718 is medium with a CVSS score of 5.4.
Which versions of Apache Superset are affected by CVE-2022-43718?
Apache Superset version 1.5.2 and prior versions, as well as version 2.0.0 and 2.0.0-rc1 and rc2, are affected by CVE-2022-43718.
What is the impact of CVE-2022-43718?
CVE-2022-43718 can lead to possible XSS attack vectors that can be performed by authenticated users with database connection update permissions.
How can I fix CVE-2022-43718?
To fix CVE-2022-43718, you should update Apache Superset to version 1.5.3 or higher, or version 2.1.0 or higher.
Where can I find more information about CVE-2022-43718?
You can find more information about CVE-2022-43718 on the Apache Superset documentation and the official Apache mailing list.