CVE-2022-43721

MEDIUM

Apache Superset <2.0.0 - Open Redirect

Title source: llm
STIX 2.1

Description

An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.

References (1)

Core 1
Core References
Mailing List, Vendor Advisory vendor-advisory
https://lists.apache.org/thread/s6sqt5jmcv6qxtvdot1t5tpt57v439kg

Scores

CVSS v3 5.4
EPSS 0.0072
EPSS Percentile 72.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (3)
apache/superset 2.0.0 (3 CPE variants)
apache/superset < 1.5.2
pypi/apache-superset 0PyPI
Published Jan 16, 2023
Tracked Since Feb 18, 2026