PT-2023-5203 · Apache · Apache Airflow Hdfs Provider
Anupamas01
·
Published
2023-08-28
·
Updated
2023-09-19
·
CVE-2023-41267
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Airflow HDFS Provider versions prior to 4.1.1
Description
The issue is related to the Apache Airflow HDFS Provider, where a documentation error pointed users to an incorrect pip package. This package name was unclaimed, potentially allowing an attacker to claim it and provide malicious code that would be executed upon installation. The Airflow team has taken ownership of the package and fixed the documentation in version 4.1.1.
Recommendations
For versions prior to 4.1.1, update to version 4.1.1 or later to resolve the issue. As a temporary workaround, consider avoiding the installation of unverified pip packages until the documentation is corrected. Restrict access to the package installation process to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow Hdfs Provider