High severity7.5NVD Advisory· Published Aug 11, 2023· Updated Jun 17, 2026
CVE-2023-39553
CVE-2023-39553
Description
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.
Apache Airflow Drill Provider is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection with DrillHook giving an opportunity to read files on the Airflow server. This issue affects Apache Airflow Drill Provider: before 2.4.3. It is recommended to upgrade to a version that is not affected.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-airflow-providers-apache-drillPyPI | < 2.4.3 | 2.4.3 |
Affected products
3- cpe:2.3:a:apache:apache-airflow-providers-apache-drill:*:*:*:*:*:*:*:*Range: <2.4.3
- Range: 0
Patches
Vulnerability mechanics
References
8- www.openwall.com/lists/oss-security/2023/08/11/1nvdMailing ListPatchThird Party AdvisoryWEB
- github.com/apache/airflow/pull/33074nvdPatchWEB
- lists.apache.org/thread/ozpl0opmob49rkcz8svo8wkxyw1395sfnvdMailing ListPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-mq4v-6vg4-796cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-39553ghsaADVISORY
- github.com/apache/airflow/commit/394a727ac2c18d58978bf186a7a92923460ec110ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2023-136.yamlghsaWEB
- www.openwall.com/lists/oss-security/2023/08/11/1ghsaWEB
News mentions
0No linked articles in our index yet.