Description
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset versions before 3.0.0.
Published: 2023-11-28
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-2972 An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset versions before 3.0.0.
Github GHSA Github GHSA GHSA-hc74-9vjm-c9xv Apache Superset Open Redirect vulnerability
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-02T19:23:39.566Z

Reserved: 2023-09-11T11:20:01.211Z

Link: CVE-2023-42502

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-11-28T17:15:07.907

Modified: 2024-11-21T08:22:40.920

Link: CVE-2023-42502

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses