In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Arbitrary Code Execution vulnerabilities in an interactive lesson.
Start learningUpgrade apache-superset
to version 0.34.0 or higher.
apache-superset is a modern, enterprise-ready business intelligence web application.
Affected versions of this package are vulnerable to Arbitrary Code Execution. Crafted yaml
files could lead to code execution.
For example: code_exec: !!python/object/apply:subprocess.check_output ['ls']
An arbitrary code execution can happen here also due to clickjacking attacks, that can happen because there is no default XFO header.