PT-2023-5054 · Apache · Apache Superset

Naveen Sunkavally

·

Published

2023-07-26

·

Updated

2025-02-05

·

CVE-2023-39265

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Superset versions up to and including 2.1.0
Description The issue is related to the use of alternative driver names when importing a database, which could allow a remote attacker to create arbitrary files and gain unauthorized access to protected information by connecting to SQLite databases. This could result in unexpected file creation on Superset web servers. If Apache Superset is using a SQLite database for its metadata, it could lead to more severe vulnerabilities related to confidentiality and integrity.
Recommendations For Apache Superset versions up to and including 2.1.0, update to a version later than 2.1.0 to resolve the issue. As a temporary workaround, consider restricting the use of alternative driver names like sqlite+pysqlite to minimize the risk of exploitation. Avoid using database imports that could lead to incorrect registration of SQLite database connections until the issue is resolved.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-05600
BIT-SUPERSET-2023-39265
CVE-2023-39265
GHSA-FM4Q-J8G4-C9J4

Affected Products

Apache Superset