Safety vulnerability ID: 61038
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of Apache Superset are vulnerable to remote code execution due to crafted Python object persistence. An attacker gaining write access to the Superset metadata database can persist a malicious object that leads to execution on the web backend. The attack requires significant privileges to access an internal component.
https://lists.apache.org/thread/6qk1zscc06yogxxfgz2bh2bvz6vh9g7h
Latest version: 4.1.2
A modern, enterprise-ready business intelligence web application
If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. This vulnerability impacts Apache Superset versions 1.5.0 up to and including 2.1.0. See CVE-2023-37941.
MISC:https://lists.apache.org/thread/6qk1zscc06yogxxfgz2bh2bvz6vh9g7h: https://lists.apache.org/thread/6qk1zscc06yogxxfgz2bh2bvz6vh9g7h
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application