Apache Superset Import Dashboards Remote Code Execution

Strike ID:
E18-0p6d1
CVSS:
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
False Positive:
t
Variants:
1
Year:
2018

Description

A remote code execution exists in Apache Superset through the 'Import Dashboards' feature. The vulnerability exists as a result of an insecure 'pickle' deserialization, allowing execution of arbitrary methods from the Python library. An authenticated attacker can therefore execute arbitrary code on the target system under the user that runs the 'gunicorn' webserver.

CVE