CVE-2023-35798
Published: Jun 27, 2023
Modified: Oct 7, 2024
Description
Input Validation vulnerability in Apache Software Foundation Apache Airflow ODBC Provider, Apache Software Foundation Apache Airflow MSSQL Provider.This vulnerability is considered low since it requires DAG code to use `get_sqlalchemy_connection` and someone with access to connection resources specifically updating the connection to exploit it. This issue affects Apache Airflow ODBC Provider: before 4.0.0; Apache Airflow MSSQL Provider: before 3.4.1. It is recommended to upgrade to a version that is not affected
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache Airflow ODBC Provider | affected 0 - < 4.0.0 |
Apache Software Foundation | Apache Airflow MSSQL Provider | affected 0 - < 3.4.1 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now