Apache SupersetGHSA-hc74-9vjm-c9xv
Apache Superset Open Redirect vulnerability
Medium5.4CVE-2023-42502 · Published Nov 28, 2023 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 3.0.0 | 3.0.0 |
Details and references
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset versions before 3.0.0.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-601
- Also known as
- BIT-superset-2023-42502, CVE-2023-42502, PYSEC-2026-1182
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Nov 272023 | Apache Superset has Incorrect Default Permissions CVE-2023-42501Medium4.3fixed in 2.1.2 | Medium4.3 | 2.1.2 |
| Nov 272023 | Apache Superset Cross-site Scripting vulnerability CVE-2023-43701Medium4.3fixed in 2.1.2 | Medium4.3 | 2.1.2 |
| Nov 282023 | Apache Superset Allocation of Resources Without Limits or Throttling vulnerability CVE-2023-42504Medium6.5fixed in 3.0.0 | Medium6.5 | 3.0.0 |
| Nov 282023 | Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability CVE-2023-42505Medium4.3fixed in 3.0.0 | Medium4.3 | 3.0.0 |
| Nov 282023 | Apache Superset - Elevation of Privilege CVE-2023-40610High7.3fixed in 2.1.2 | High7.3 | 2.1.2 |
| Dec 192023 | Apache Superset uncontrolled resource consumption CVE-2023-46104Medium6.5fixed in 2.1.2, 3.1.0rc1 | Medium6.5 | 2.1.2, 3.1.0rc1 |