Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39459
HistoryFeb 28, 2023 - 9:32 a.m.

Remote Code Execution (RCE)

2023-02-2809:32:14
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
remote code execution
apache_airflow_providers_google
vulnerability
cloud_sql.py
improper validation
cloud sql provider
malicious code

EPSS

0.002

Percentile

58.0%

apache_airflow_providers_google is vulnerable to Remote Code Execution (RCE). The vulnerability is due to improper validation for th cloud sql provider parameter in the _download_sql_proxy_if_needed function of cloud_sql.py which allows an attacker to upload and execute malicious code on the system.

EPSS

0.002

Percentile

58.0%

Related for VERACODE:39459