In Apache Airflow 2.3.0 through 2.3.4, part of a url was unnecessarily formatted, allowing for possible information extraction.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
https://github.com/apache/airflow/pull/26337 | patch third party advisory |
https://lists.apache.org/thread/z20x8m16fnhxdkoollv53w1ybsts687t | vendor advisory |