-
Notifications
You must be signed in to change notification settings - Fork 14.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
update superset 3.1.0/3.1.1 dependency "selenium 3.141.0" #26992
Comments
Oops... I was mistaken when I closed this, sorry. |
superset 3.1.1 is also affected |
in relation to #25933 |
The fix seems to be deemed a breaking change, so it'll have to wait until the breaking change window opens for Superset 5.0. I added the PR to that project board for consensus. We may also consider making the move toward Playwright, and thus Selenium wouldn't be an issue any more. |
Thank you @rusackas for adding the ticket! |
this is also CVE related as the other tickets you closed, you might also want to close this ticket as the other ones? |
as there was no reaction now I will close this ticket now because it is based on CVE. |
Bug description
The docker inspector marks the image of superset 3.1.0 with a finding of selenium 3.141.0
https://scout.docker.com/vulnerabilities/id/CVE-2023-5590?s=pypa&n=selenium&t=pypi&vr=%3C4.14.0&utm_source=desktop&utm_medium=ExternalLink
CVSS = 7.5
fixed with 4.14.0
=> an update to 4.14.0 (or newer) should be done
How to reproduce the bug
download docker image
open in docker scout
Screenshots/recordings
Superset version
3.1.0
3.1.1
Python version
3.9
Node version
16
Browser
Chrome
Additional context
V3.0.3 is also affected
Checklist
The text was updated successfully, but these errors were encountered: