NA

CVE-2023-40272

Published: 17/08/2023 Updated: 24/08/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Apache Airflow Spark Provider, versions prior to 4.1.3, is affected by a vulnerability that allows an malicious user to pass in malicious parameters when establishing a connection giving an opportunity to read files on the Airflow server. It is recommended to upgrade to a version that is not affected.

Vulnerable Product Search on Vulmon Subscribe to Product

apache apache-airflow-providers-apache-spark