CVE-2018-8021 – Apache Superset < 0.23 - Remote Code Execution
https://notcve.org/view.php?id=CVE-2018-8021
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation. Las versiones anteriores a la 0.23 de Superset empleaban un método inseguro de carga de la biblioteca pickle para deserializar datos, lo que conduce a una posible ejecución remota de código. Nota: Superset 0.23 se lanzó antes que cualquier distribución de Superset bajo la Apache Software Foundation. Apache Superset version 0.23 suffers from a remote code execution vulnerability. • https://www.exploit-db.com/exploits/45933 https://github.com/r3dxpl0it/Apache-Superset-Remote-Code-Execution-PoC-CVE-2018-8021 https://github.com/apache/incubator-superset/pull/4243 • CWE-502: Deserialization of Untrusted Data •