vendor:
Superset
by:
David May
9.8
CVSS
CRITICAL
Remote Code Execution
94
CWE
Product Name: Superset
Affected Version From: Any before 0.23
Affected Version To: 0.23
Patch Exists: YES
Related CWE: CVE-2018-8021
CPE: a:apache:superset
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04
2018
Apache Superset < 0.23 - Remote Code Execution
A vulnerability in Apache Superset before 0.23 allows remote code execution. An attacker can exploit this vulnerability by sending a malicious pickle file to the server, which can be used to execute arbitrary code. This exploit was originally disclosed to the Apache Superset team in May 2018 and the fix had already been in place, but not backported.
Mitigation:
Upgrade to Apache Superset version 0.23 or later.