Sploitus

CVE-2023-37941

3 known exploits for CVE-2023-37941

If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal' component that is typically only accessible directly by the system administrator and the superset process itself. Gaining access to that database should be difficult and require significant privileges. This vulnerability impacts Apache Superset versions 1.5.0 up to and including 2.1.0. Users are recommended to upgrade to version 2.1.1 or later.

Affected products
Apache Superset
Apache Superset
≤ 2.1.0
Fix
Available
CVSS 3.1
6.6 MEDIUM
EPSS
35.5% (98th percentile)
Weakness
CWE-502
NVD status
Modified
Published
2023-09-06
CVE-2023-37941 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2023-37941

Proof-of-concept code and exploit modules indexed by Sploitus