Количество 2
Количество 2
CVE-2021-32609
больше 4 лет назад
Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a chart with a malicious title, injecting html (including scripts) into the page.
CVSS3: 5.4
EPSS: Низкий
GHSA-f8vc-f28w-x9c9
больше 3 лет назад
Apache Superset Cross-site Scripting (XSS) vulnerability on the Explore page
CVSS3: 5.4
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-32609 Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a chart with a malicious title, injecting html (including scripts) into the page. | CVSS3: 5.4 | 9% Низкий | больше 4 лет назад | |
GHSA-f8vc-f28w-x9c9 Apache Superset Cross-site Scripting (XSS) vulnerability on the Explore page | CVSS3: 5.4 | 9% Низкий | больше 3 лет назад |
Уязвимостей на страницу
20