HIGH 7.5 PyPI
Apache Airflow Drill Provider vulnerable to improper input validation
GHSA-85pf-r4c7-3j9r · CVE-2023-28707 · PYSEC-2023-3 · PYSEC-2026-1136
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Apache Software Foundation's Apache Airflow Drill Provider before 2.3.2 is vulnerable to improper input validation because the host passed in drill connection is not sanitized.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2023-28707
- WEB https://github.com/apache/airflow/pull/30215
- WEB https://github.com/apache/airflow/commit/63d9b24aad0b4b9397682ddac1ea5824354789b3
- PACKAGE https://github.com/apache/airflow
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2023-3.yaml
- WEB https://lists.apache.org/thread/dfoj7q1nd0vhhsl8fjg63z4j6mfmdxtk
- WEB https://www.openwall.com/lists/oss-security/2023/04/07/1
- WEB http://www.openwall.com/lists/oss-security/2023/04/07/1
Ready to move
Start Securing
Free, no credit card | First findings in minutes