CVE-2021-28125
Apache Superset Open Redirect
6.1
MEDIUM
CVSS 3.1
EPSS 63.8%
描述
Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link.
如何修補 CVE-2021-28125
要修補 CVE-2021-28125,請將受影響套件升級到下列已修補版本。
- —升級至 1.0.2 或更新版本
- —升級至 1.1.0 或更新版本
- —升級至 1.1.0 或更新版本
- —未列出修補版本
- —未列出修補版本
CVE-2021-28125 正在被利用嗎?
可能 — EPSS 為 63.8%,屬於高被利用機率區間,建議優先修補。
受影響套件(5)
- from 0, < 1.0.2
- from 0, < 1.1.0
- from 0, < 1.1.0
- from 0, <= 0.34.0
- from 0, <= 0.34.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |