Apache Airflow Spark Provider Improper Input Validation vulnerability
High severity
GitHub Reviewed
Published
Aug 17, 2023
to the GitHub Advisory Database
•
Updated Feb 13, 2025
Package
Affected versions
< 4.1.3
Patched versions
4.1.3
Description
Published by the National Vulnerability Database
Aug 17, 2023
Published to the GitHub Advisory Database
Aug 17, 2023
Reviewed
Aug 17, 2023
Last updated
Feb 13, 2025
Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection giving an opportunity to read files on the Airflow server.
It is recommended to upgrade to a version that is not affected.
References