Apache SupersetGHSA-pfwg-rxf4-97c3
Open Redirect in Apache Superset
Medium6.1CVE-2021-28125 · Published Oct 6, 2021 · updated Jul 13, 2026
Apache Superset prior to 1.1.0 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 1.1.0 | 1.1.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-601
- Also known as
- BIT-superset-2021-28125, CVE-2021-28125, PYSEC-2021-128, PYSEC-2026-3078
- nvd.nist.gov/vuln/detail/CVE-2021-28125
- github.com/apache/superset/commit/eb35b804acf4d84cb70d02743e04b8afebbee029
- github.com/advisories/GHSA-pfwg-rxf4-97c3
- github.com/apache/superset
- github.com/pypa/advisory-database/tree/main/vulns/apache-superset/PYSEC-2021-128.yaml
- lists.apache.org/thread.html/r89b5d0dd35c1adc9624b48d6247729c73b2641b32754226661368434%40%3Cdev.superset.apache.org%3E
- lists.apache.org/thread.html/r89b5d0dd35c1adc9624b48d6247729c73b2641b32754226661368434@%3Cdev.superset.apache.org%3E
- www.openwall.com/lists/oss-security/2021/04/27/2
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 242022 | Apache Superset allowed for database connections password leak for authenticated users | High6.5 | 1.3.2 |
| May 242022 | Apache Superset Cross-site Scripting (XSS) vulnerability on the Explore page | Medium5.4 | 1.2.0 |
| May 242022 | Apache Superset SQL Injection when template processing is enabled | High8.8 | 1.3.1 |
| Apr 142022 | SQL injection in apache-superset | Critical9.8 | 1.4.2 |
| Feb 22022 | Insufficiently Protected Credentials in Apache Superset | High6.5 | 1.4.0 |
| Apr 302021 | Plaintext password leak in Apache Superset | High8.1 | 0.37.2 |