Medium severity5.4NVD Advisory· Published Jan 16, 2023· Updated Jun 17, 2026
CVE-2022-43720
CVE-2022-43720
Description
An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the toast message displayed when a user deletes that specific CSS template record. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-supersetPyPI | <= 1.5.2 | — |
Affected products
7- osv-coords2 versions
< 1.5.3+ 1 more
- (no CPE)range: < 1.5.3
- (no CPE)range: <= 1.5.2
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-fpmr-qmgh-42x2ghsaADVISORY
- lists.apache.org/thread/jts6x56kghr9mbowb653bk70pl81jp8lnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-43720ghsaADVISORY
News mentions
0No linked articles in our index yet.