PT-2023-5203 · Apache · Apache Airflow Hdfs Provider

Anupamas01

·

Published

2023-08-28

·

Updated

2023-09-19

·

CVE-2023-41267

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Airflow HDFS Provider versions prior to 4.1.1
Description The issue is related to the Apache Airflow HDFS Provider, where a documentation error pointed users to an incorrect pip package. This package name was unclaimed, potentially allowing an attacker to claim it and provide malicious code that would be executed upon installation. The Airflow team has taken ownership of the package and fixed the documentation in version 4.1.1.
Recommendations For versions prior to 4.1.1, update to version 4.1.1 or later to resolve the issue. As a temporary workaround, consider avoiding the installation of unverified pip packages until the documentation is corrected. Restrict access to the package installation process to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

BDU:2023-05809
CVE-2023-41267
GHSA-5HJ9-M76G-XRC8

Affected Products

Apache Airflow Hdfs Provider