Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-37941— Apache Superset: Metadata db write access can lead to remote code execution

Quick assessment

Affected
Apache Software Foundation Apache Superset
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Superset是美国阿帕奇(Apache)基金会的一个数据可视化和数据探索平台。 Apache Superset 2.1.0 版本及之前版本存在代码问题漏洞,该漏洞源于如果具有对 Apache Superset 元数据数据库的写访问权限,他们就可以保留一个特制的 Python 对象,这可能会导致在 Superset 的 Web 后端上远程执行代码。

CVSS 6.6 · Medium EPSS 35.45% · P98
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-37941

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Superset: Metadata db write access can lead to remote code execution
Source: CVE Program / CVE List V5
Vulnerability Description
If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal' component that is typically only accessible directly by the system administrator and the superset process itself. Gaining access to that database should be difficult and require significant privileges. This vulnerability impacts Apache Superset versions 1.5.0 up to and including 2.1.0. Users are recommended to upgrade to version 2.1.1 or later.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
Source: CVE Program / CVE List V5
Vulnerability Title
Apache Superset 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache Superset是美国阿帕奇(Apache)基金会的一个数据可视化和数据探索平台。 Apache Superset 2.1.0 版本及之前版本存在代码问题漏洞,该漏洞源于如果具有对 Apache Superset 元数据数据库的写访问权限,他们就可以保留一个特制的 Python 对象,这可能会导致在 Superset 的 Web 后端上远程执行代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Superset 1.5.0 ~ 2.1.0 -

II. Public POCs for CVE-2023-37941

# POC Description Source Link Shenlong Link
1 Exploit on the default cache of superset by using pickle https://github.com/Barroqueiro/CVE-2023-37941 POC Details
2 None https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/Apache%20Superset%20Python%20Pickle%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E5%AF%BC%E8%87%B4%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%20CVE-2023-37941.md POC Details
3 https://github.com/vulhub/vulhub/blob/master/superset/CVE-2023-37941/README.md POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-37941

请登录查看更多情报信息。

Exploits & Public PoCs for CVE-2023-37941 (1)

Mailing List Discussions for CVE-2023-37941 (1)

Same Patch Batch · Apache Software Foundation · 2023-09-06 · 8 CVEs total

CVE-2023-36387 5.4 MEDIUM Apache Superset: Improper API permission for low privilege users
CVE-2023-27523 5.0 MEDIUM Apache Superset: Improper data permission validation on Jinja templated queries
CVE-2023-32672 4.3 MEDIUM Apache Superset: SQL parser edge case bypasses data access authorization
CVE-2023-39264 4.3 MEDIUM Apache Superset: Stack traces enabled by default
CVE-2023-36388 4.3 MEDIUM Apache Superset: Improper API permission for low privilege users allows for SSRF
CVE-2023-27526 4.3 MEDIUM Apache Superset: Improper Authorization check on import charts
CVE-2023-39265 3.8 LOW Apache Superset: Possible Unauthorized Registration of SQLite Database Connections

IV. Related Vulnerabilities

V. Comments for CVE-2023-37941

No comments yet


Leave a comment