CVE-2023-42502: Apache Superset: Open Redirect Vulnerability
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset versions before 3.0.0.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Apache Superset vulnerability?
The vulnerability ID for this Apache Superset vulnerability is CVE-2023-42502.
What is the title of this Apache Superset vulnerability?
The title of this Apache Superset vulnerability is 'Open Redirect Vulnerability'.
What is the severity of CVE-2023-42502?
The severity of CVE-2023-42502 is medium (4.8).
How does this vulnerability affect Apache Superset?
This vulnerability affects Apache Superset versions before 3.0.0.
How can an attacker exploit this vulnerability?
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, redirecting users to that site when clicking on the specific dataset.
What is the remedy for this vulnerability?
The remedy for this vulnerability is to update Apache Superset to version 3.0.0 or later.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [1](https://lists.apache.org/thread/n8348f194d8o8mln3oxd0s8jdl5bxbmn), [2](http://www.openwall.com/lists/oss-security/2023/11/28/3), [3](https://nvd.nist.gov/vuln/detail/CVE-2023-42502).