Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-mm87-c3x2-6f89: Apache Airflow JDBC Provider Improper Input Validation vulnerability

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider. Airflow JDBC Provider Connection’s [Connection URL] parameters had no restrictions, which made it possible to implement RCE attacks via different type JDBC drivers, obtain airflow server permission. This issue affects Apache Airflow JDBC Provider: before 4.0.0.

ghsa
#vulnerability#apache#git#rce
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2023-22886

Apache Airflow JDBC Provider Improper Input Validation vulnerability

Moderate severity GitHub Reviewed Published Jun 29, 2023 to the GitHub Advisory Database • Updated Jun 30, 2023

Package

pip apache-airflow-providers-jdbc (pip)

Affected versions

< 4.0.0

Published to the GitHub Advisory Database

Jun 29, 2023

Last updated

Jun 30, 2023

Related news

CVE-2023-22886

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider. Airflow JDBC Provider Connection’s [Connection URL] parameters had no restrictions, which made it possible to implement RCE attacks via different type JDBC drivers, obtain airflow server permission. This issue affects Apache Airflow JDBC Provider: before 4.0.0.