CVE-2023-22884: Apache Airflow, Apache Airflow MySQL Provider: Arbitrary file read via MySQL provider in Apache Airflow
Published Jan 21, 2023
·Updated
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Airflow MySQL Provider: before 4.0.0.
Affected Software
2 affected components
Apache Airflow<2.5.1
Apache Apache-airflow-providers-mysql<4.0.0
Remediation
Patch Available
Event History
Jan 21, 2023
CVE Published
via MITRE·01:02 PM
Data Sourced
via MITRE·01:02 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-22884.
2
What is the severity of CVE-2023-22884?
The severity of CVE-2023-22884 is critical with a CVSS score of 9.8.
3
Which software is affected by CVE-2023-22884?
Apache Airflow versions before 2.5.1 and Apache Airflow MySQL Provider versions before 4.0.0 are affected by CVE-2023-22884.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-77.
5
How can I fix CVE-2023-22884?
To fix CVE-2023-22884, update to Apache Airflow version 2.5.1 or later and Apache Airflow MySQL Provider version 4.0.0 or later.