Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2023-0373 | Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints |
![]() |
GHSA-7222-r37x-8q3m | Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 07 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-04-07T15:04:38.899Z
Reserved: 2022-10-24T10:12:53.061Z
Link: CVE-2022-43719

Updated: 2024-08-03T13:40:06.300Z

Status : Modified
Published: 2023-01-16T11:15:10.513
Modified: 2025-04-07T15:15:40.867
Link: CVE-2022-43719

No data.

No data.