Record summary

CVE-2023-37941 has a selected CVSS score of 6.6 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal' component that is typically only accessible directly by the system administrator and the superset process itself. Gaining access to that database should be difficult and require significant privileges. This vulnerability impacts Apache Superset versions 1.5.0 up to and including 2.1.0. Users are recommended to upgrade to version 2.1.1 or later.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Aug 12, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 27, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: unknown

VulnCheck, CVE List1.5.0 to ≤ 2.1.0affected

Default status: unaffected

CVE List1.5.0 to ≤ 2.1.0affected
GitHub Advisory1.5.0 to < 2.1.1 · Fixed in 2.1.1affected

Proofs of concept

2

Catalogued exploits

MetasploitApache Superset Signed Cookie RCEMetasploit exploitby Naveen Sunkavally +3 moreNot analyzed1 file

Ruby · linked to 3 vulnerabilities

Metasploit

PoC details

Repository PoCs

GitHubBarroqueiro/CVE-2023-37941Repository PoCby BarroqueiroStars: 1Not analyzed3 files

226.5 KiB

GitHub

PoC details

References

4