Description
Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs.
No analysis available yet.
Remediation
Vendor Workaround
Upgrade to Apache Superset 1.3.2 or higher
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0024 | Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs. |
Github GHSA |
GHSA-5fp8-c45m-256p | Improper Encoding or Escaping of Output in Apache Superset |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T03:30:37.952Z
Reserved: 2021-10-11T00:00:00.000Z
Link: CVE-2021-42250
No data.
Status : Modified
Published: 2021-11-17T15:15:08.277
Modified: 2024-11-21T06:27:27.540
Link: CVE-2021-42250
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA