Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-05218
HistoryJan 18, 2023 - 12:00 a.m.

Apache Superset Cross-Site Request Forgery Vulnerability

2023-01-1800:00:00
China National Vulnerability Database
www.cnvd.org.cn
11
apache superset
csrf
vulnerability
user input
validation
legacy rest apis
server intranet resources

EPSS

0.005

Percentile

77.7%

A cross-site request forgery vulnerability exists in Apache Superset, a data visualization and data exploration platform from the Apache Foundation. The vulnerability stems from the failure of two legacy REST APIs for granting and requesting access to properly validate user input, which could be exploited by attackers to probe server intranet resources.

EPSS

0.005

Percentile

77.7%