First published: Tue Nov 28 2023(Updated: )
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset versions before 3.0.0.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Superset | <3.0.0 | |
pip/apache-superset | <3.0.0 | 3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Apache Superset vulnerability is CVE-2023-42502.
The title of this Apache Superset vulnerability is 'Open Redirect Vulnerability'.
The severity of CVE-2023-42502 is medium (4.8).
This vulnerability affects Apache Superset versions before 3.0.0.
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, redirecting users to that site when clicking on the specific dataset.
The remedy for this vulnerability is to update Apache Superset to version 3.0.0 or later.
You can find more information about this vulnerability at the following references: [1](https://lists.apache.org/thread/n8348f194d8o8mln3oxd0s8jdl5bxbmn), [2](http://www.openwall.com/lists/oss-security/2023/11/28/3), [3](https://nvd.nist.gov/vuln/detail/CVE-2023-42502).