GHSA-2rx4-9f5h-9gjf
Dashboard / Vulnerabilities / GHSA-2rx4-9f5h-9gjf
GHSA-2rx4-9f5h-9gjf
Summary: Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configuration
Details: Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. In order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to change the connection object in this manner. Operators should upgrade to provider version 7.0.0 which has removed the vulnerability.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-33234, https://github.com/apache/airflow, https://lists.apache.org/thread/n1vpgl6h2qsdm52o9m2tx1oo86tl4gnq
Affected packages
Package
Name: apache-airflow-providers-cncf-kubernetes
Purl: pkg:pypi/apache-airflow-providers-cncf-kubernetes
Affected ranges
Type: ECOSYSTEM
Events:
