Apache Superset CVE-2018-8021 Remote Code Execution
BID:106066
Info
Apache Superset CVE-2018-8021 Remote Code Execution
| Bugtraq ID: | 106066 |
| Class: | Design Error |
| CVE: |
CVE-2018-8021 |
| Remote: | Yes |
| Local: | No |
| Published: | May 17 2018 12:00AM |
| Updated: | May 17 2018 12:00AM |
| Credit: | David May ([email protected]) |
| Vulnerable: |
Apache Superset 0.23 |
| Not Vulnerable: | |
Discussion
Apache Superset CVE-2018-8021 Remote Code Execution
Apache Superset is prone to remote code execution vulnerability; fixes are available.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Apache Superset 0.23 and prior versions are vulnerable.
Apache Superset is prone to remote code execution vulnerability; fixes are available.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Apache Superset 0.23 and prior versions are vulnerable.
Exploit / POC
Apache Superset CVE-2018-8021 Remote Code Execution
The researcher has created an exploit code to demonstrate the issue. Please see the references for more information.
The researcher has created an exploit code to demonstrate the issue. Please see the references for more information.
References
Apache Superset CVE-2018-8021 Remote Code Execution
References:
References:
- Apache Superset Home page (Superset Home Page)
- Exploit (Exploit DB)
- Superset Github ()