Apache SupersetGHSA-fpmr-qmgh-42x2
Apache Superset vulnerable to Injection
Medium5.4CVE-2022-43720 · Published Jan 16, 2023 · updated Jul 7, 2026
An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the toast message displayed when a user deletes that specific CSS template record. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | <= 1.5.2 | No fix yet |
| <= 2.0.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-74
- Also known as
- BIT-superset-2022-43720, CVE-2022-43720, PYSEC-2026-782
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 162023 | Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints | High8.8 | No fix yet |
| Jan 162023 | Apache Superset is vulnerable to Cross-Site Scripting (XSS) | Medium5.4 | No fix yet |
| Jan 162023 | Apache Superset vulnerable to Cross-site Scripting | Medium5.4 | No fix yet |
| Jan 162023 | Apache Superset's SQL Alchemy connector vulnerable to SQL Injection | Medium5.4 | No fix yet |
| Jan 162023 | Apache Superset has Improper Access Control | Medium5.3 | No fix yet |
| Jan 162023 | Apache Superset Open Redirect vulnerability | Medium5.4 | No fix yet |