Apache Airflow ODBC Provider: Remote code execution vulnerability
CVE-2023-34395

7.8HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
27 June 2023

Summary

A privilege escalation vulnerability exists within the Apache Airflow ODBC Provider due to unverified control over ODBC driver parameters. This flaw permits the loading of arbitrary dynamic-link libraries, which can lead to potential command execution by unauthorized users. Users of versions prior to 4.0.0 should take immediate action to upgrade and secure their systems.

Affected Version(s)

Apache Airflow ODBC Provider 0 < 4.0.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

KmhlYXJ0
.