Stored cross-site scripting in Apache Superset - CVE-2023-49657

 

Stored cross-site scripting in Apache Superset - CVE-2023-49657

Published: January 23, 2024


Vulnerability identifier: #VU85735
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2023-49657
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user with create/update permissions on charts or dashboards can permanently inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.


Affected software

Apache Superset

How to mitigate CVE-2023-49657

Install update from vendor's website.

Apache Superset - update to 3.0.3

External References

Related Security Bulletins