Apache Superset Cross-site Scripting vulnerability
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Nov 27, 2023 
          to the GitHub Advisory Database
          •
          Updated Nov 28, 2023 
      
  
Description
        Published by the National Vulnerability Database
      Nov 27, 2023 
    
  
        Published to the GitHub Advisory Database
      Nov 27, 2023 
    
  
        Reviewed
      Nov 28, 2023 
    
  
        Last updated
      Nov 28, 2023 
    
  
Improper payload validation and an improper REST API response type, made it possible for an authenticated malicious actor to store malicious code into Chart's metadata, this code could get executed if a user specifically accesses a specific deprecated API endpoint. This issue affects Apache Superset versions prior to 2.1.2.
Users are recommended to upgrade to version 2.1.2, which fixes this issue.
References