CVE-2023-37941
If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal' component that is typically only accessible directly by the system administrator and the superset process itself. Gaining access to that database should be difficult and require significant privileges. This vulnerability impacts Apache Superset versions 1.5.0 up to and including 2.1.0. Users are recommended to upgrade to version 2.1.1 or later.
- Affected products
- Apache Superset
- Apache Superset
- ≤ 2.1.0
- Fix
- Available
- CVSS 3.1
- 6.6 MEDIUM
- EPSS
- 35.5% (98th percentile)
- Weakness
- CWE-502
- NVD status
- Modified
- Published
- 2023-09-06
CVE-2023-37941 at NVD
3 known exploits for CVE-2023-37941
Proof-of-concept code and exploit modules indexed by Sploitus