Apache SupersetGHSA-9f88-wg5r-947j
Apache Superset vulnerable to Cross-site Scripting
Medium5.4CVE-2022-43717 · Published Jan 16, 2023 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | <= 1.5.2 | No fix yet |
| <= 2.0.0 | No fix yet |
Details and references
Dashboard rendering does not sufficiently sanitize the content of markdown components leading to possible XSS attack vectors that can be performed by authenticated users with create dashboard permissions. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-79
- Also known as
- BIT-superset-2022-43717, CVE-2022-43717, PYSEC-2026-779
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 162023 | Apache Superset has Improper Access Control CVE-2022-45438Medium5.3no fix yet | Medium5.3 | No fix yet |
| Jan 162023 | Apache Superset Open Redirect vulnerability CVE-2022-43721Medium5.4no fix yet | Medium5.4 | No fix yet |
| Jan 162023 | Apache Superset vulnerable to Injection CVE-2022-43720Medium5.4no fix yet | Medium5.4 | No fix yet |
| Jan 162023 | Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints CVE-2022-43719High8.8no fix yet | High8.8 | No fix yet |
| Jan 162023 | Apache Superset is vulnerable to Cross-Site Scripting (XSS) CVE-2022-43718Medium5.4no fix yet | Medium5.4 | No fix yet |
| Jan 162023 | Apache Superset's SQL Alchemy connector vulnerable to SQL Injection CVE-2022-41703Medium5.4no fix yet | Medium5.4 | No fix yet |