QID 980513
QID 980513: Python (pip) Security Update for superset (GHSA-pfwg-rxf4-97c3)
Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-pfwg-rxf4-97c3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-pfwg-rxf4-97c3 -
github.com/advisories/GHSA-pfwg-rxf4-97c3
CVEs related to QID 980513
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pfwg-rxf4-97c3 | superset |
|