Lucene search

K
cvelistApacheCVELIST:CVE-2022-43719
HistoryJan 16, 2023 - 10:10 a.m.

CVE-2022-43719 Apache Superset: Cross Site Request Forgery (CSRF) on accept, request access API

2023-01-1610:10:27
CWE-352
apache
www.cve.org
4
apache superset
cross site request forgery
csrf
rest api
vulnerability
version 1.5.2
version 2.0.0

AI Score

8.8

Confidence

High

EPSS

0.005

Percentile

77.7%

Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Apache Superset",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThan": "2.0.1",
        "status": "affected",
        "version": "2.0.0",
        "versionType": "semver"
      },
      {
        "lessThanOrEqual": "1.5.2",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

AI Score

8.8

Confidence

High

EPSS

0.005

Percentile

77.7%

Related for CVELIST:CVE-2022-43719