Lucene search

K
githubGitHub Advisory DatabaseGHSA-85PF-R4C7-3J9R
HistoryApr 07, 2023 - 3:30 p.m.

Apache Airflow Drill Provider vulnerable to improper input validation

2023-04-0715:30:38
CWE-20
GitHub Advisory Database
github.com
7
apache airflow
drill provider
input validation
vulnerability
apache software foundation

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

59.0%

Apache Software Foundation’s Apache Airflow Drill Provider before 2.3.2 is vulnerable to improper input validation because the host passed in drill connection is not sanitized.

Affected configurations

Vulners
Node
apacheapache-airflow-providers-apache-drillRange<2.3.2

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

59.0%

Related for GHSA-85PF-R4C7-3J9R