Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider. Apache Airflow Drill Provider is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection with DrillHook giving an opportunity to read files on the Airflow server. This issue affects Apache Airflow Drill Provider: before 2.4.3. It is recommended to upgrade to a version that is not affected.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://github.com/apache/airflow/pull/33074 | patch |
https://lists.apache.org/thread/ozpl0opmob49rkcz8svo8wkxyw1395sf | patch vendor advisory mailing list |
http://www.openwall.com/lists/oss-security/2023/08/11/1 | patch mailing list third party advisory |