CVE-2023-22884
Published on: Not Yet Published
Last Modified on: 01/31/2023 05:18:00 PM UTC
Certain versions of Airflow from Apache contain the following vulnerability:
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Airflow MySQL Provider: before 4.0.0.
- CVE-2023-22884 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
- Affected Vendor/Software:
Apache Software Foundation - Apache Airflow version = 0
- Affected Vendor/Software:
Apache Software Foundation - Apache Airflow MySQL Provider version = 0
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Move local_infile option from extra to hook parameter by potiuk · Pull Request #28811 · apache/airflow · GitHub | github.com text/html |
![]() |
No Description Provided | lists.apache.org text/html |
![]() |
Related QID Numbers
- 378078 Zoom Client for Meetings Multiple Security Vulnerabilities (ZSB-23004)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Apache | Airflow | All | All | All | All |
Application | Apache | Airflow Mysql Provider | All | All | All | All |
- cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*:
- cpe:2.3:a:apache:airflow_mysql_provider:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-22884 : Improper Neutralization of Special Elements used in a Command 'Command Injection' vulnerability… twitter.com/i/web/status/1… | 2023-01-21 14:02:34 |