oss-sec mailing list archives

CVE-2023-25692: Apache Airflow Google Provider: Google Cloud Sql Provider Denial Of Service


From: Jarek Potiuk <potiuk () apache org>
Date: Thu, 23 Feb 2023 17:43:10 +0000

Severity: low

Description:

Improper Input Validation vulnerability in the Apache Airflow Google Provider.

This issue affects Apache Airflow Google Provider versions before 8.10.0.

Credit:

Xie Jianming of Caiji Sec Team (finder)

References:

https://github.com/apache/airflow/pull/29499
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2023-25692


Current thread: