Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update superset 3.1.0/3.1.1 dependency "selenium 3.141.0" #26992

Closed
3 tasks done
nigzak opened this issue Feb 2, 2024 · 7 comments · Fixed by #25933
Closed
3 tasks done

update superset 3.1.0/3.1.1 dependency "selenium 3.141.0" #26992

nigzak opened this issue Feb 2, 2024 · 7 comments · Fixed by #25933
Assignees

Comments

@nigzak
Copy link
Contributor

nigzak commented Feb 2, 2024

Bug description

The docker inspector marks the image of superset 3.1.0 with a finding of selenium 3.141.0

https://scout.docker.com/vulnerabilities/id/CVE-2023-5590?s=pypa&n=selenium&t=pypi&vr=%3C4.14.0&utm_source=desktop&utm_medium=ExternalLink
CVSS = 7.5
fixed with 4.14.0

=> an update to 4.14.0 (or newer) should be done

How to reproduce the bug

download docker image
open in docker scout

Screenshots/recordings

image

Superset version

3.1.0
3.1.1

Python version

3.9

Node version

16

Browser

Chrome

Additional context

V3.0.3 is also affected

Checklist

  • I have searched Superset docs and Slack and didn't find a solution to my problem.
  • I have searched the GitHub issue tracker and didn't find a similar bug report.
  • I have checked Superset's logs for errors and if I found a relevant Python stacktrace, I included it here as text in the "additional context" section.
@nigzak nigzak changed the title update superset 3.1.0 dependency "selenium 3.141.0" because of security high findings update superset 3.1.0 dependency "selenium 3.141.0" Feb 2, 2024
@rusackas rusackas closed this as completed Feb 2, 2024
@rusackas rusackas reopened this Feb 2, 2024
@rusackas
Copy link
Member

rusackas commented Feb 2, 2024

Oops... I was mistaken when I closed this, sorry.

@nigzak nigzak changed the title update superset 3.1.0 dependency "selenium 3.141.0" update superset 3.1.0/3.1.1 dependency "selenium 3.141.0" Feb 21, 2024
@nigzak
Copy link
Contributor Author

nigzak commented Feb 21, 2024

superset 3.1.1 is also affected

@nigzak
Copy link
Contributor Author

nigzak commented Feb 21, 2024

in relation to #25933

@rusackas
Copy link
Member

The fix seems to be deemed a breaking change, so it'll have to wait until the breaking change window opens for Superset 5.0. I added the PR to that project board for consensus. We may also consider making the move toward Playwright, and thus Selenium wouldn't be an issue any more.

@michael-s-molina
Copy link
Member

The fix seems to be deemed a breaking change, so it'll have to wait until the breaking change window opens for Superset 5.0. I added the PR to that project board for consensus.

Thank you @rusackas for adding the ticket!

@nigzak
Copy link
Contributor Author

nigzak commented May 23, 2024

Hi @michael-s-molina

this is also CVE related as the other tickets you closed, you might also want to close this ticket as the other ones?

@nigzak
Copy link
Contributor Author

nigzak commented May 26, 2024

as there was no reaction now I will close this ticket now because it is based on CVE.

@nigzak nigzak closed this as completed May 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants