HTTP: Apache Superset URL Shortener Open Redirect

This signature detects attempts to exploit a known vulnerability against Apache Superset. A successful attack can lead to arbitrary code execution.

Extended Description

Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link.

Affected Products

Apache superset

Short Name
HTTP:APACHE:SS-URLRDRCT-RCE
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Apache CVE-2021-28125 Open Redirect Shortener Superset URL
Release Date
06/30/2021
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3397
False Positive
Unknown
Vendors

Apache

CVSS Score

5.8

Found a potential security threat?