Skip to content

Vulnerable issues (CVE) with dependencies in Superset #23621

@hash-data

Description

@hash-data

Superset currently using :
WTForms version: 2.3.3

In there is a CVE vulnerability that can be found here https://pyup.io/v/42852/f17/
Tried to update the version but there is an error while running the flask-server with the newest version of WTForms: pallets-eco/wtforms#781 (issue listed here)

Superset Currently using flask app-builder that is using sqlalchemy <1.5 restrict (all versions of flask app builder depend on sqlalchemy < 1.5)
Which have a CVE vulnerability for more info visit: https://pyup.io/v/51668/f17/

Metadata

Metadata

Assignees

Labels

#bugBug report

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions