Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-37941— Apache Superset: Metadata db write access can lead to remote code execution

CVSS 6.6 · Medium EPSS 84.24% · P99
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-37941

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Superset: Metadata db write access can lead to remote code execution
Source: NVD (National Vulnerability Database)
Vulnerability Description
If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal' component that is typically only accessible directly by the system administrator and the superset process itself. Gaining access to that database should be difficult and require significant privileges. This vulnerability impacts Apache Superset versions 1.5.0 up to and including 2.1.0. Users are recommended to upgrade to version 2.1.1 or later.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
可信数据的反序列化
Source: NVD (National Vulnerability Database)
Vulnerability Title
Apache Superset 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache Superset是美国阿帕奇(Apache)基金会的一个数据可视化和数据探索平台。 Apache Superset 2.1.0 版本及之前版本存在代码问题漏洞,该漏洞源于如果具有对 Apache Superset 元数据数据库的写访问权限,他们就可以保留一个特制的 Python 对象,这可能会导致在 Superset 的 Web 后端上远程执行代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
Apache Software FoundationApache Superset 1.5.0 ~ 2.1.0 -

II. Public POCs for CVE-2023-37941

#POC DescriptionSource LinkShenlong Link
1Exploit on the default cache of superset by using picklehttps://github.com/Barroqueiro/CVE-2023-37941POC Details
2Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/Apache%20Superset%20Python%20Pickle%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E5%AF%BC%E8%87%B4%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%20CVE-2023-37941.mdPOC Details
3https://github.com/vulhub/vulhub/blob/master/superset/CVE-2023-37941/README.mdPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-37941

登录查看更多情报信息。

Same Patch Batch · Apache Software Foundation · 2023-09-06 · 8 CVEs total

CVE-2023-363875.4 MEDIUMApache Superset: Improper API permission for low privilege users
CVE-2023-275235.0 MEDIUMApache Superset: Improper data permission validation on Jinja templated queries
CVE-2023-326724.3 MEDIUMApache Superset: SQL parser edge case bypasses data access authorization
CVE-2023-392644.3 MEDIUMApache Superset: Stack traces enabled by default
CVE-2023-363884.3 MEDIUMApache Superset: Improper API permission for low privilege users allows for SSRF
CVE-2023-275264.3 MEDIUMApache Superset: Improper Authorization check on import charts
CVE-2023-392653.8 LOWApache Superset: Possible Unauthorized Registration of SQLite Database Connections

IV. Related Vulnerabilities

V. Comments for CVE-2023-37941

No comments yet


Leave a comment