PT-2023-5338 · Apache · Apache Airflow Sqoop Provider

·

CVE-2023-27604

·

Publicado

2023-08-25

·

Atualizado

2026-07-07

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Airflow Sqoop Provider versions prior to 4.0.0
Description The issue is related to insufficient input validation, which can be exploited by a remote attacker to execute arbitrary code. This can be achieved by passing parameters with connections, making it possible to implement RCE attacks via sqoop import --connect, and obtain Airflow server permissions. The attacker needs to be logged in and have authorization to create or edit connections.
Recommendations To resolve the issue, upgrade to a version that is not affected, specifically version 4.0.0 or later. As a temporary workaround, consider restricting access to the sqoop import --connect command to minimize the risk of exploitation. Additionally, limit the ability to create or edit connections to authorized personnel only.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-05966
CVE-2023-27604
GHSA-G3M9-PR5M-4CVP
PYSEC-2026-1142

Produtos afetados

Apache Airflow Sqoop Provider