Description
An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the toast message displayed when a user deletes that specific CSS template record. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0459 | An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the toast message displayed when a user deletes that specific CSS template record. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0. |
Github GHSA |
GHSA-fpmr-qmgh-42x2 | Apache Superset vulnerable to Injection |
References
History
Mon, 07 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-04-07T15:03:05.455Z
Reserved: 2022-10-24T10:13:23.347Z
Link: CVE-2022-43720
Updated: 2024-08-03T13:40:06.549Z
Status : Modified
Published: 2023-01-16T11:15:10.587
Modified: 2025-04-07T15:15:41.140
Link: CVE-2022-43720
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA