Description
Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link.
References (2)
Core 2
Core References
Mailing List, Third Party Advisory x_refsource_misc
https://lists.apache.org/thread.html/r89b5d0dd35c1adc9624b48d6247729c73b2641b32754226661368434%40%3Cdev.superset.apache.org%3E
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/04/27/2
Scores
CVSS v3
6.1
EPSS
0.0258
EPSS Percentile
85.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-601
Status
published
Products (3)
apache/superset
< 1.0.1
pypi/apache-superset
0 - 1.1.0PyPI
pypi/superset
0PyPI
Published
Apr 27, 2021
Tracked Since
Feb 18, 2026