356
VMScore

CVE-2021-42250

Published: 17/11/2021 Updated: 25/04/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache superset

Mailing Lists

Description: Improper output neutralization for Logs A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs Mitigation: Upgrade to Apache Superset 132 or higher Credit: Found and reported by Duxiaoman Financial Security Team ...