First published: Mon Jan 16 2023(Updated: )
Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by authenticated users with database connection update permissions. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Superset | <=1.5.2 | |
Apache Superset | =2.0.0 | |
Apache Superset | =2.0.0-rc1 | |
Apache Superset | =2.0.0-rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-43718 is medium with a CVSS score of 5.4.
Apache Superset version 1.5.2 and prior versions, as well as version 2.0.0 and 2.0.0-rc1 and rc2, are affected by CVE-2022-43718.
CVE-2022-43718 can lead to possible XSS attack vectors that can be performed by authenticated users with database connection update permissions.
To fix CVE-2022-43718, you should update Apache Superset to version 1.5.3 or higher, or version 2.1.0 or higher.
You can find more information about CVE-2022-43718 on the Apache Superset documentation and the official Apache mailing list.