Skip to content

Apache Superset Deserialization of Untrusted Data vulnerability

Moderate severity GitHub Reviewed Published Sep 6, 2023 to the GitHub Advisory Database • Updated Nov 8, 2023

Package

pip apache-superset (pip)

Affected versions

>= 1.5.0, <= 2.1.0

Patched versions

2.1.1

Description

If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal' component that is typically only accessible directly by the system administrator and the superset process itself. Gaining access to that database should be difficult and require significant privileges. This vulnerability impacts Apache Superset versions 1.5.0 up to and including 2.1.0. Users are recommended to upgrade to version 2.1.1 or later.

References

Published by the National Vulnerability Database Sep 6, 2023
Published to the GitHub Advisory Database Sep 6, 2023
Reviewed Sep 8, 2023
Last updated Nov 8, 2023

Severity

Moderate
6.6
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
High
Privileges required
High
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CVE ID

CVE-2023-37941

GHSA ID

GHSA-fj4x-m62j-wvwg

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.