An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the toast message displayed when a user deletes that specific CSS template record. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-04-07T15:03:05.455Z
Reserved: 2022-10-24T10:13:23.347Z
Link: CVE-2022-43720

Updated: 2024-08-03T13:40:06.549Z

Status : Modified
Published: 2023-01-16T11:15:10.587
Modified: 2025-04-07T15:15:41.140
Link: CVE-2022-43720

No data.