CVE-2018-8021: Critical severity apache superset vulnerability
Published Nov 7, 2018
·Updated
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation.
Affected Software
2 affected componentsFixes available
Apache Superset<0.23
pip/superset<0.23
0.23
Remediation
Patch Available
Event History
Nov 7, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Nov 9, 2018
Advisory Published
05:40 PM
Frequently Asked Questions
1
What is CVE-2018-8021?
CVE-2018-8021 is a vulnerability in Superset versions prior to 0.23 which allows for possible remote code execution.
2
How severe is CVE-2018-8021?
CVE-2018-8021 has a severity rating of 9.8 (Critical).
3
How does CVE-2018-8021 affect Superset?
CVE-2018-8021 affects Superset versions prior to 0.23.
4
Is there a fix available for CVE-2018-8021?
Yes, Superset 0.23 and above are not affected by CVE-2018-8021.
5
Where can I find more information about CVE-2018-8021?
More information about CVE-2018-8021 can be found on the NVD website.