StackRadar

CVE-2023-47248

Critical

Advisory

Published 9 Nov 2023In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.145
96th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
1 of 1
affected package

PyArrow: Arbitrary code execution when loading a malicious data file

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
pyarrowpypi0.14.0, 0.15.1, 5.0.0, 10.0.0+2 more14.0.19
OSV records
GHSA-5wvp-7f3h-6wmm
Also known as
PYSEC-2023-238

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
supersetcloudposse1.2.01 of 1See more

superset cloudposse 1.2.0

1 of the 1 container images this version deploys carry CVE-2023-47248.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
pyarrow@0.15.1
14.0.1

Open the chart page →

5,851
fadicetic0.3.11 of 25See more

fadi cetic 0.3.1

1 of the 25 container images this version deploys carry CVE-2023-47248.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
pyarrow@0.15.1
14.0.1

Open the chart page →

52,919
deepstackgeek-cookbookVerified publisher1.5.21 of 2See more

deepstack geek-cookbook 1.5.2

1 of the 2 container images this version deploys carry CVE-2023-47248.

Container imageDigestPackageFixed in
robmarkcole/deepstack-ui:latest410275726459
pyarrow@5.0.0
14.0.1

Open the chart page →

5,305
supersetinseefrlab1.4.01 of 4See more

superset inseefrlab 1.4.0

1 of the 4 container images this version deploys carry CVE-2023-47248.

Container imageDigestPackageFixed in
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
pyarrow@5.0.0
14.0.1

Open the chart page →

7,129
mlflow-controllermlflow-deployment-controller0.1.81 of 2See more

mlflow-controller mlflow-deployment-controller 0.1.8

1 of the 2 container images this version deploys carry CVE-2023-47248.

Container imageDigestPackageFixed in
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
pyarrow@10.0.1
14.0.1

Open the chart page →

8,957
mlflow-servermlflowserver0.1.91 of 3See more

mlflow-server mlflowserver 0.1.9

1 of the 3 container images this version deploys carry CVE-2023-47248.

Container imageDigestPackageFixed in
buntha/mlflow:2.1.1154542cc3083
pyarrow@10.0.1
14.0.1

Open the chart page →

5,804
spark-standalonedmwm-bigdataVerified publisher0.1.01 of 2See more

spark-standalone dmwm-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-47248.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
pyarrow@0.14.0
14.0.1

Open the chart page →

6,147
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2023-47248.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
pyarrow@10.0.0
14.0.1

Open the chart page →

4,085
spark-standalonegradiant-bigdataVerified publisher0.1.01 of 2See more

spark-standalone gradiant-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-47248.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
pyarrow@0.14.0
14.0.1

Open the chart page →

6,147
mlflowmondata-helm-chartsVerified publisher0.2.31 of 1See more

mlflow mondata-helm-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2023-47248.

Container imageDigestPackageFixed in
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
pyarrow@11.0.0
14.0.1

Open the chart page →

3,811
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2023-47248.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
pyarrow@11.0.0
14.0.1

Open the chart page →

5,456

Container images carrying it

9 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
amancevice/superset:0.35.212a0a9e66550
pyarrow@0.15.1
14.0.1
2
gradiant/spark:2.4.4-python-alpine97657d56e927
pyarrow@0.14.0
14.0.1
2
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
pyarrow@5.0.0
14.0.1
1
buntha/mlflow:2.1.1154542cc3083
pyarrow@10.0.1
14.0.1
1
evk02/mlflow:2.2.1ef6ff257ef35
pyarrow@11.0.0
14.0.1
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
pyarrow@10.0.0
14.0.1
1
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
pyarrow@11.0.0
14.0.1
1
robmarkcole/deepstack-ui:latest410275726459
pyarrow@5.0.0
14.0.1
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
pyarrow@10.0.1
14.0.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.