Affected versions:

- Apache Superset 1.5.0 through 2.1.0

Description:

If an attacker gains write access to the Apache Superset metadata database, 
they could persist a specifically crafted Python object that may lead to remote 
code execution on Superset's web backend. This vulnerability impacts Apache 
Superset versions 1.5.0 up to and including 2.1.0.

Credit:

Dinis Cruz, [email protected] (finder)
Naveen Sunkavally (Horizon3.ai) (finder)

References:

https://superset.apache.org
https://www.cve.org/CVERecord?id=CVE-2023-37941

Reply via email to