First published: Wed Nov 07 2018(Updated: )
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/superset | <0.23 | 0.23 |
Apache Superset | <0.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8021 is a vulnerability in Superset versions prior to 0.23 which allows for possible remote code execution.
CVE-2018-8021 has a severity rating of 9.8 (Critical).
CVE-2018-8021 affects Superset versions prior to 0.23.
Yes, Superset 0.23 and above are not affected by CVE-2018-8021.
More information about CVE-2018-8021 can be found on the NVD website.