Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection giving an opportunity to read files on the Airflow server. It is recommended to upgrade to a version that is not affected.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: apache

Published: 2023-08-17T13:52:30.647Z

Updated: 2023-08-17T13:52:30.647Z

Reserved: 2023-08-12T06:29:53.016Z


Link: CVE-2023-40272

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-08-17T14:15:10.083

Modified: 2023-08-24T17:00:07.203


Link: CVE-2023-40272

JSON object: View

cve-icon Redhat Information

No data.