Description:

Improper output neutralization for Logs. A specific Apache Superset HTTP 
endpoint allowed for an authenticated user to forge log entries or inject 
malicious content into logs.

Mitigation:

Upgrade to Apache Superset 1.3.2 or higher

Credit:

Found and reported by Duxiaoman Financial Security Team

Reply via email to