An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset versions before 3.0.0.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-2972 An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset versions before 3.0.0.
Github GHSA Github GHSA GHSA-hc74-9vjm-c9xv Apache Superset Open Redirect vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-02T19:23:39.566Z

Reserved: 2023-09-11T11:20:01.211Z

Link: CVE-2023-42502

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-11-28T17:15:07.907

Modified: 2024-11-21T08:22:40.920

Link: CVE-2023-42502

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.