Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fj97-2v9x-w5m4

Опубликовано: 14 авг. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability

A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and gets executed in the victim's browser when they hover over the chart, potentially leading to session hijacking or the execution of arbitrary commands on behalf of the user.

This issue affects Apache Superset: before 5.0.0.

Users are recommended to upgrade to version 5.0.0, which fixes the issue.

Пакеты

Наименование

apache-superset

pip
Затронутые версииВерсия исправления

< 5.0.0

5.0.0

EPSS

Процентиль: 8%
0.00029
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-80

Связанные уязвимости

CVSS3: 5.4
nvd
6 месяцев назад

A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and gets executed in the victim's browser when they hover over the chart, potentially leading to session hijacking or the execution of arbitrary commands on behalf of the user. This issue affects Apache Superset: before 5.0.0. Users are recommended to upgrade to version 5.0.0, which fixes the issue.

CVSS3: 5.4
fstec
6 месяцев назад

Уязвимость программного обеспечения визуализации данных Apache Superset, связанная с непринятием мер по нейтрализации script-related тэгов HTML на веб-странице, позволяющая нарушителю проводить межсайтовые сценарные атаки (XSS)

EPSS

Процентиль: 8%
0.00029
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-80