Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-43717


Dashboard rendering does not sufficiently sanitize the content of markdown components leading to possible XSS attack vectors that can be performed by authenticated users with create dashboard permissions. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.


Published

2023-01-16T11:15:10.370

Last Modified

2025-04-04T14:15:19.013

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache superset ≤ 1.5.2 Yes
Application apache superset 2.0.0 Yes
Application apache superset 2.0.0 Yes
Application apache superset 2.0.0 Yes

References