High severityNVD Advisory· Published Aug 11, 2023· Updated Feb 13, 2025
Apache Airflow Drill Provider Arbitrary File Read Vulnerability
CVE-2023-39553
Description
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.
Apache Airflow Drill Provider is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection with DrillHook giving an opportunity to read files on the Airflow server. This issue affects Apache Airflow Drill Provider: before 2.4.3. It is recommended to upgrade to a version that is not affected.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-airflow-providers-apache-drillPyPI | < 2.4.3 | 2.4.3 |
Affected products
2- Range: 0
Patches
Vulnerability mechanics
Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
8- github.com/apache/airflow/pull/33074ghsapatchWEB
- github.com/advisories/GHSA-mq4v-6vg4-796cghsaADVISORY
- lists.apache.org/thread/ozpl0opmob49rkcz8svo8wkxyw1395sfghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-39553ghsaADVISORY
- www.openwall.com/lists/oss-security/2023/08/11/1ghsaWEB
- github.com/apache/airflow/commit/394a727ac2c18d58978bf186a7a92923460ec110ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2023-136.yamlghsaWEB
- www.openwall.com/lists/oss-security/2023/08/11/1ghsaWEB
News mentions
0No linked articles in our index yet.