QID 996128
Date Published: 2023-12-04
QID 996128: Python (Pip) Security Update for apache-superset (GHSA-hc74-9vjm-c9xv)
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset versions before 3.0.0.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-hc74-9vjm-c9xv for updates and patch information.
Vendor References
- GHSA-hc74-9vjm-c9xv -
github.com/advisories/GHSA-hc74-9vjm-c9xv
CVEs related to QID 996128
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hc74-9vjm-c9xv | apache-superset |
|