CVE-2021-42250
published 2021-11-17CVE-2021-42250: Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
1.76%
75.4th percentile
Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | superset | < 1.3.2 | 1.3.2 |
| apache_software_foundation | apache_superset | Apache Superset – 1.3.1 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Encoding or Escaping of Output in Apache Superset
osv·2022-05-24
CVE-2021-42250 [HIGH] Improper Encoding or Escaping of Output in Apache Superset
Improper Encoding or Escaping of Output in Apache Superset
Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs.
GHSA
Improper Encoding or Escaping of Output in Apache Superset
ghsa·2022-05-24
CVE-2021-42250 [HIGH] CWE-116 Improper Encoding or Escaping of Output in Apache Superset
Improper Encoding or Escaping of Output in Apache Superset
Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs.
OSV
CVE-2021-42250: Improper output neutralization for Logs
osv·2021-11-17
CVE-2021-42250 CVE-2021-42250: Improper output neutralization for Logs
Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-11-17
Published