VYPR

Apache Airflow Providers Keycloak

by Apache

Source repositories

CVEs (29)

  • CVE-2023-22884CriJan 21, 2023
    risk 0.58cvss 9.8epss 0.11

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Airflow MySQL…

  • CVE-2024-42447CriAug 5, 2024
    risk 0.57cvss 9.8epss 0.01

    Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache Airflow Providers FAB: 1.2.1 (when used with Apache Airflow 2.9.3) and FAB 1.2.0 for all Airflow versions. The FAB provider prevented the user from logging out.   * FAB…

  • CVE-2023-37415HigJul 13, 2023
    risk 0.57cvss 8.8epss 0.02

    Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider. Patching on top of CVE-2023-35797 Before 6.1.2 the proxy_user option can also inject semicolon. This issue affects Apache Airflow Apache Hive Provider: before 6.1.2. …

  • CVE-2023-35797CriJul 3, 2023
    risk 0.57cvss 9.8epss 0.03

    Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects Apache Airflow Apache Hive Provider: before 6.1.1. Before version 6.1.1 it was possible to bypass the security check to RCE via principal parameter. For this…

  • CVE-2023-22886HigJun 29, 2023
    risk 0.57cvss 8.8epss 0.02

    Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider. Airflow JDBC Provider Connection’s [Connection URL] parameters had no restrictions, which made it possible to implement RCE attacks via different type JDBC drivers, obtain…

  • CVE-2023-28706CriApr 7, 2023
    risk 0.57cvss 9.8epss 0.03

    Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 6.0.0.

  • CVE-2023-25696CriFeb 24, 2023
    risk 0.57cvss 9.8epss 0.02

    Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3.

  • CVE-2023-25693CriFeb 24, 2023
    risk 0.57cvss 9.8epss 0.02

    Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1.

  • CVE-2022-46421CriDec 20, 2022
    risk 0.57cvss 9.8epss 0.03

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0.

  • CVE-2022-38649CriNov 22, 2022
    risk 0.57cvss 9.8epss 0.03

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG files. This issue…

  • CVE-2024-25141CriFeb 20, 2024
    risk 0.52cvss 9.1epss 0.01

    When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented. Users are recommended to upgrade to version 4.0.0, which fixes this issue.

  • CVE-2025-69219HigMar 9, 2026
    risk 0.50cvss 8.8epss 0.01

    A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB the same permissions as Dag Author. Since direct DB access is not usual and recommended for Airflow, the likelihood of it making…

  • CVE-2023-40195HigAug 28, 2023
    risk 0.50cvss 8.8epss 0.01

    Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflow Spark Provider. When the Apache Spark provider is installed on an Airflow deployment, an Airflow user that is authorized to…

  • CVE-2023-27604HigAug 28, 2023
    risk 0.50cvss 8.8epss 0.01

    Apache Airflow Sqoop Provider, versions before 4.0.0, is affected by a vulnerability that allows an attacker pass parameters with the connections, which makes it possible to implement RCE attacks via ‘sqoop import --connect’, obtain airflow server permissions, etc. The…

  • CVE-2023-40272HigAug 17, 2023
    risk 0.49cvss 7.5epss 0.02

    Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection giving an opportunity to read files on the Airflow server. It is recommended to upgrade to a version that…

  • CVE-2024-45033HigJan 8, 2025
    risk 0.46cvss 8.1epss 0.01

    Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed with admin CLI, the sessions for that user have not been cleared, leading to insufficient session…

  • CVE-2023-41267HigSep 14, 2023
    risk 0.44cvss 7.8epss 0.00

    In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect pip package. As this package name was unclaimed, in theory, an attacker could claim this package and provide code that would be executed when this package…

  • CVE-2022-41131HigNov 22, 2022
    risk 0.44cvss 7.8epss 0.02

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airflow allows an attacker to execute arbtrary commands in the task execution context, without write access to DAG files. This issue…

  • CVE-2023-39553HigAug 11, 2023
    risk 0.42cvss 7.5epss 0.02

    Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider. Apache Airflow Drill Provider is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection with DrillHook giving an…

  • CVE-2023-28710HigApr 7, 2023
    risk 0.42cvss 7.5epss 0.02

    Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects Apache Airflow Spark Provider: before 4.0.1.

Page 1 of 2