{"id":"CVE-2022-43719","aliases":["GHSA-7222-r37x-8q3m","BIT-superset-2022-43719","PYSEC-2026-775"],"title":"Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints","summary":"Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","vendor":"apache-superset","product":"apache-superset","ecosystem":"pip","affected":["apache-superset <= 1.5.2","apache-superset"],"published":"2023-01-16","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-7222-r37x-8q3m","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-43719"},{"url":"https://github.com/apache/superset"},{"url":"https://lists.apache.org/thread/xc309h2dphrkg33154djf3nqlh2xc1c0"}],"tags":["osv","pip"],"epss":0.00572,"epssPercentile":0.46022,"ingestedAt":"2026-07-08T18:25:46.698Z","slug":"CVE-2022-43719","body":"## Overview\n\nTwo legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.\n\n## Affected packages\n\n- `apache-superset <= 1.5.2`\n- `apache-superset`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}