Vulnerability Intelligence Report
Apache Superset: Cross Site Request Forgery (CSRF) on accept, request access API
CVE-2022-43719
Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:0.57%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-352 ↗CWE-352 Cross-Site Request Forgery (CSRF)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Apache Software Foundation | Apache Superset | 2.0.0 < 2.0.1 (affected), 0 <= 1.5.2 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.567%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Apache Software Foundation · Vendor · USA |
| Reserved | 2022-10-24T10:12:53 |
| Published | 2023-01-16T10:10:27 |
| Last Updated | 2025-04-07T15:04:38 |
Community Chatter & Buzz