Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-0020 Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link.
Github GHSA Github GHSA GHSA-pfwg-rxf4-97c3 Open Redirect in Apache Superset
Fixes

Solution

No solution given by the vendor.


Workaround

https://github.com/apache/superset/pull/13461

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-03T21:33:17.571Z

Reserved: 2021-03-10T00:00:00

Link: CVE-2021-28125

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-27T10:15:09.693

Modified: 2024-11-21T05:59:07.970

Link: CVE-2021-28125

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.