High severity7.2NVD Advisory· Published May 30, 2023· Updated Jul 2, 2026
CVE-2023-33234
CVE-2023-33234
Description
Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection.
In order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to change the connection object in this manner. Operators should upgrade to provider version 7.0.0 which has removed the vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-airflow-providers-cncf-kubernetesPyPI | >= 5.0.0, < 7.0.0 | 7.0.0 |
Affected products
2- Range: 5.0.0
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-2rx4-9f5h-9gjfghsaADVISORY
- lists.apache.org/thread/n1vpgl6h2qsdm52o9m2tx1oo86tl4gnqnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-33234ghsaADVISORY
News mentions
0No linked articles in our index yet.