ZeroHour

CVE-2018-8021

PoC
CVSS 3.0
9.8 critical
EPSS
53%p99
Published
()
Modified
Description

Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation.

Vendors
apache
Products
superset
Weakness
CWE-502
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.