HIGH 7.5 PyPI

apache-airflow-providers-apache-drill Improper Input Validation vulnerability

GHSA-mq4v-6vg4-796c · CVE-2023-39553 · PYSEC-2023-136 · PYSEC-2026-1137

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.

Apache Airflow Drill Provider is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection with DrillHook giving an opportunity to read files on the Airflow server.
This issue affects Apache Airflow Drill Provider before 2.4.3.
It is recommended to upgrade to a version that is not affected.

Ready to move

Start Securing

Free, no credit card | First findings in minutes