PT-2023-5045 · Apache · Apache Superset

Dinis Cruz

+1

·

Published

2023-07-11

·

Updated

2025-02-05

·

CVE-2023-37941

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Superset versions 1.5.0 through 2.1.0
Description The issue is related to a software vulnerability in Apache Superset, specifically a deserialization mechanism flaw. If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata database is an internal component, typically only accessible directly by the system administrator and the Superset process itself, and gaining access to it should be difficult and require significant privileges. Approximately 15,849 results were found, indicating potential exposure.
Recommendations To resolve the issue, users are recommended to upgrade to Apache Superset version 2.1.1 or later. As a temporary workaround, consider restricting access to the Superset metadata database to minimize the risk of exploitation. Additionally, system administrators should ensure that the Superset process itself and the metadata database are properly secured to prevent unauthorized access.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-05589
BIT-SUPERSET-2023-37941
CVE-2023-37941
GHSA-FJ4X-M62J-WVWG

Affected Products

Apache Superset