Description
Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0373 | Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints |
Github GHSA |
GHSA-7222-r37x-8q3m | Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints |
References
History
Mon, 07 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-04-07T15:04:38.899Z
Reserved: 2022-10-24T10:12:53.061Z
Link: CVE-2022-43719
Updated: 2024-08-03T13:40:06.300Z
Status : Modified
Published: 2023-01-16T11:15:10.513
Modified: 2025-04-07T15:15:40.867
Link: CVE-2022-43719
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA