Critical severityNVD Advisory· Published Feb 24, 2023· Updated Feb 13, 2025
Sqoop Apache Airflow Provider Remote Code Execution Vulnerability
CVE-2023-25693
Description
Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider.
This issue affects Apache Airflow Sqoop Provider versions before 3.1.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-airflow-providers-apache-sqoopPyPI | < 3.1.1 | 3.1.1 |
Affected products
2- Range: 0
Patches
Vulnerability mechanics
Synthesis attempt was rejected by the grounding validator. Re-run pending.
References
5- github.com/apache/airflow/pull/29500ghsapatchWEB
- github.com/advisories/GHSA-j69x-v4wc-3fpfghsaADVISORY
- lists.apache.org/thread/79qn8g5xbq036f8crb115obvr22l52q4ghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-25693ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2023-314.yamlghsaWEB
News mentions
0No linked articles in our index yet.