Deployments that pass externally sourced file or folder names to the Google Drive hook are affected, including wildcard gcs_to_gdrive transfers from buckets where another trust principal can create objects. This commonly includes external data producers or ingest-only service accounts that can write to the source bucket but do not author the DAG.
The attacker needs control of a file or folder name supplied to the Google Drive query, such as the ability to create an object in a source bucket used by a wildcard gcs_to_gdrive transfer. The controlled name must contain an apostrophe and injected query clauses.
An attacker can broaden the Google Drive match and steer the file or folder resolved by the hook. Uploads can be directed to an attacker-named folder, and downloads may return an attacker-placed file because the most recently modified match is selected.
Upgrade the Apache Airflow Google provider to version 22.6.0 or later. Until then, limit write access to buckets used for wildcard gcs_to_gdrive transfers and avoid passing file or folder names from untrusted sources to the Google Drive hook.