
Cloud Vulnerability DB
A community-led vulnerabilities database
Apache Superset was found to contain a Remote Code Execution vulnerability identified as CVE-2020-13948. The vulnerability was discovered and disclosed in September 2020, affecting authenticated users who could craft specific requests through templated features in the Apache Superset platform (NVD).
The vulnerability stemmed from exposing class objects or modules that allowed unsafe chained access within the Apache Superset system. This security issue was identified as having the same root cause as previous security bugs in the platform (Apache Lists).
The vulnerability allowed authenticated users to potentially execute remote code on the affected systems through specially crafted requests, posing a significant security risk to Apache Superset installations (OSS Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."