Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-2rx4-9f5h-9gjf: Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configuration

Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection.

In order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to change the connection object in this manner. Operators should upgrade to provider version 7.0.0 which has removed the vulnerability.

ghsa
#vulnerability#apache#git#kubernetes#rce
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2023-33234

Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configuration

High severity GitHub Reviewed Published Jul 6, 2023 to the GitHub Advisory Database • Updated Jul 6, 2023

Package

pip apache-airflow-providers-cncf-kubernetes (pip)

Affected versions

>= 5.0.0, < 7.0.0

Published to the GitHub Advisory Database

Jul 6, 2023

Related news

CVE-2023-33234

Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. In order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to change the connection object in this manner.  Operators should upgrade to provider version 7.0.0 which has removed the vulnerability.

ghsa: Latest News

GHSA-49cc-xrjf-9qf7: SFTPGo allows administrators to restrict command execution from the EventManager