Open Redirect in Apache Superset
Moderate severity
GitHub Reviewed
Published
Oct 6, 2021
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Apr 27, 2021
Reviewed
Oct 6, 2021
Published to the GitHub Advisory Database
Oct 6, 2021
Last updated
Jan 27, 2023
Apache Superset prior to 1.1.0 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link.
References