Open Redirect Affecting apache-superset package, versions [,3.0.0)
Threat Intelligence
EPSS
0.09% (39th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-APACHESUPERSET-6092416
- published 29 Nov 2023
- disclosed 28 Nov 2023
- credit Amit Laish
Introduced: 28 Nov 2023
CVE-2023-42502 Open this link in a new tabHow to fix?
Upgrade apache-superset
to version 3.0.0 or higher.
Overview
apache-superset is a modern, enterprise-ready business intelligence web application.
Affected versions of this package are vulnerable to Open Redirect when the dataset link updating process is manipulated. An attacker can change a dataset link to an untrusted site by spoofing the HTTP Host header. This is only exploitable if the attacker is authenticated and has update datasets permission.
References
CVSS Scores
version 3.1