Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-9f88-wg5r-947j: Apache Superset vulnerable to Cross-site Scripting

Dashboard rendering does not sufficiently sanitize the content of markdown components leading to possible XSS attack vectors that can be performed by authenticated users with create dashboard permissions. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.

ghsa
#xss#apache#git#auth

Apache Superset vulnerable to Cross-site Scripting

Moderate severity GitHub Reviewed Published Jan 16, 2023 • Updated Jan 20, 2023

Related news

CVE-2022-43717

Dashboard rendering does not sufficiently sanitize the content of markdown components leading to possible XSS attack vectors that can be performed by authenticated users with create dashboard permissions. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.