CVE-2022-43720
Severity CVSS v4.0:
Pending analysis
Type:
CWE-74
Injection
Publication date:
16/01/2023
Last modified:
07/04/2025
Description
An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the toast message displayed when a user deletes that specific CSS template record. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.<br />
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:* | 1.5.2 (including) | |
| cpe:2.3:a:apache:superset:2.0.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:superset:2.0.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:superset:2.0.0:rc2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



