Beveiligingsadvies

CVE-2021-32609

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-10-18 14:30:12
Laatst bijgewerkt 2024-08-03 23:25:30
Toegewezen door apache
CVSS-score geen score
Status PUBLISHED

Beschrijving

Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a chart with a malicious title, injecting html (including scripts) into the page.