Safety vulnerability ID: 61038
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Apache-superset 2.1.1 includes a fix for CVE-2023-37941: If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend.
https://lists.apache.org/thread/6qk1zscc06yogxxfgz2bh2bvz6vh9g7h
Latest version: 4.1.1
A modern, enterprise-ready business intelligence web application
If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. This vulnerability impacts Apache Superset versions 1.5.0 up to and including 2.1.0. See CVE-2023-37941.
MISC:https://lists.apache.org/thread/6qk1zscc06yogxxfgz2bh2bvz6vh9g7h: https://lists.apache.org/thread/6qk1zscc06yogxxfgz2bh2bvz6vh9g7h
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application