SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-8021

Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution.

CRITICAL 9.8EPSS 52.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 52.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
52.76% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-502
Affected
apache/superset
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.