CVE-2021-42250

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/11/2021
Last modified:
25/04/2022

Description

Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:* 1.3.2 (excluding)