Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2021-04-27T09:27:22

Updated: 2024-08-03T21:33:17.571Z

Reserved: 2021-03-10T00:00:00

Link: CVE-2021-28125

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-27T10:15:09.693

Modified: 2024-11-21T05:59:07.970

Link: CVE-2021-28125

cve-icon Redhat

No data.