Skip to content
Apache SupersetGHSA-cj7g-h7rf-h8j9

Apache Superset OS Command Injection

High8.8CVE-2020-13948 · Published May 24, 2022 · updated Feb 5, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
< 0.37.10.37.1
Details and references

While investigating a bug report on Apache Superset, it was determined that an authenticated user could craft requests via a number of templated text fields in the product that would allow arbitrary access to Python’s `os` package in the web application process in versions < 0.37.1. It was thus possible for an authenticated user to list and access files, environment variables, and process information. Additionally it was possible to set environment variables for the current process, create and update files in folders writable by the web process, and execute arbitrary programs accessible by the web process. All other operations available to the `os` package in Python were also available, even if not explicitly enumerated in this CVE.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-78
Also known as
BIT-superset-2020-13948, CVE-2020-13948, PYSEC-2020-222

More Apache Superset advisories

All Apache Superset
DateAdvisory
May 242022Apache Superset SQL Injection when template processing is enabled
CVE-2021-41971High8.8fixed in 1.3.1
May 242022Apache Superset Cross-site Scripting (XSS) vulnerability on the Explore page
CVE-2021-32609Medium5.4fixed in 1.2.0
May 242022Apache Superset allowed for database connections password leak for authenticated users
CVE-2021-41972High6.5fixed in 1.3.2
May 242022Improper Encoding or Escaping of Output in Apache Superset
CVE-2021-42250High6.5fixed in 1.3.2
May 242022Apache Superset Stored XSS on Dashboard markdown
CVE-2021-27907Medium5.4fixed in 0.38.1
Apr 142022SQL injection in apache-superset
CVE-2022-27479Critical9.8fixed in 1.4.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.