PT-2023-7467 · Apache · Apache Airflow Drill Provider

Kai Zhao

·

Published

2023-03-21

·

Updated

2024-10-23

·

CVE-2023-28707

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Airflow Drill Provider versions prior to 2.3.2
Description The issue is related to improper input validation in the Apache Airflow Drill Provider. This can allow a remote attacker to impact the confidentiality of protected information. The vulnerability is due to the host passed in the drill connection not being sanitized.
Recommendations For versions prior to 2.3.2, update to version 2.3.2 or later to resolve the issue. As a temporary workaround, consider sanitizing the host input in the drill connection to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-08510
CVE-2023-28707
GHSA-85PF-R4C7-3J9R
PYSEC-2023-3

Affected Products

Apache Airflow Drill Provider