GHSA-r2f6-6928-fh8f
Dashboard / Vulnerabilities / GHSA-r2f6-6928-fh8f
GHSA-r2f6-6928-fh8f
Summary: Apache Airflow Spark Provider Improper Input Validation vulnerability
Details: Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection giving an opportunity to read files on the Airflow server. It is recommended to upgrade to a version that is not affected.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-40272, https://lists.apache.org/thread/t03gktyzyor20rh06okd91jtqmw6k1l7, http://www.openwall.com/lists/oss-security/2023/08/17/1, http://www.openwall.com/lists/oss-security/2023/08/18/1
Affected packages
Package
Name: apache-airflow-providers-apache-spark
Purl: pkg:pypi/apache-airflow-providers-apache-spark
Affected ranges
Type: ECOSYSTEM
Events:
