
Cloud Vulnerability DB
A community-led vulnerabilities database
Apache Superset versions up to and including 1.1 were affected by a Cross-Site Scripting (XSS) vulnerability identified as CVE-2021-32609. The vulnerability was discovered in the Explore page functionality and was disclosed on October 15, 2021. The issue was identified by Oscar Arnflo and reported to the Apache Superset team (Openwall Report).
The vulnerability is classified as CWE-79 (Cross-site Scripting) and stems from improper sanitization of titles on the Explore page. This security flaw allows attackers with Explore access to inject malicious HTML content, including scripts, into the page through chart titles (Openwall Report).
When exploited, this vulnerability allows attackers to inject arbitrary HTML and JavaScript code into the application through chart titles, potentially leading to the execution of malicious scripts in users' browsers when viewing affected pages (Openwall Report).
Users are advised to upgrade their Apache Superset installations to a version newer than 1.1, which contains the fix for this vulnerability (Openwall Report).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."