imPC@ndo IT

Tracker / CVE-2021-42250

CVE-2021-42250

Medium 6.5

Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs.

Affected products and versions

apache superset · … → 1.3.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References