Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0373 | Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints |
Github GHSA |
GHSA-7222-r37x-8q3m | Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 07 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-04-07T15:04:38.899Z
Reserved: 2022-10-24T10:12:53.061Z
Link: CVE-2022-43719
Updated: 2024-08-03T13:40:06.300Z
Status : Modified
Published: 2023-01-16T11:15:10.513
Modified: 2025-04-07T15:15:40.867
Link: CVE-2022-43719
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA