CVE-2023-37941
MEDIUM EXPLOITEDApache Superset 1.5.0-2.1.0 - Remote Code Execution via Metadata Database Deserialization
Title source: llmExploitation Summary
CVE-2023-37941 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Barroqueiro.
AI-analyzed exploit summary This PoC exploits CVE-2023-37941, a deserialization vulnerability in Apache Superset's built-in cache mechanism. It uses a malicious pickle payload to achieve remote code execution by updating cached values in the metadata database.
Description
If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal' component that is typically only accessible directly by the system administrator and the superset process itself. Gaining access to that database should be difficult and require significant privileges. This vulnerability impacts Apache Superset versions 1.5.0 up to and including 2.1.0. Users are recommended to upgrade to version 2.1.1 or later.
Exploits (1)
This PoC exploits CVE-2023-37941, a deserialization vulnerability in Apache Superset's built-in cache mechanism. It uses a malicious pickle payload to achieve remote code execution by updating cached values in the metadata database.
References (2)
Scores
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H