Apache AirflowPYSEC-2023-136
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.
High7.5CVE-2023-39553 · Published Aug 11, 2023 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | < 2.4.3 | 2.4.3 |
Changes since it was listed
| Date | Change |
|---|---|
| Sep 24 | Severity: Unrated to High |
Details and references
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider. Apache Airflow Drill Provider is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection with DrillHook giving an opportunity to read files on the Airflow server. This issue affects Apache Airflow Drill Provider: before 2.4.3. It is recommended to upgrade to a version that is not affected.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- NVD
- Also known as
- CVE-2023-39553, GHSA-mq4v-6vg4-796c, PYSEC-2026-1137
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 52023 | Apache Airflow Execution with Unnecessary Privileges CVE-2023-39508High8.8fixed in 2.6.0b1 | High8.8 | 2.6.0b1 |
| Aug 232023 | Apache Airflow missing Certificate Validation CVE-2023-39441Medium5.9fixed in 2.7.0 | Medium5.9 | 2.7.0 |
| Aug 232023 | Apache Airflow Session Fixation vulnerability CVE-2023-40273High8.0fixed in 2.7.0rc2 | High8.0 | 2.7.0rc2 |
| Aug 232023 | Apache Airflow denial of service vulnerability CVE-2023-37379High8.1fixed in 2.7.0b1 | High8.1 | 2.7.0b1 |
| Jul 122023 | Apache Airflow Incorrect Authorization vulnerability CVE-2023-35908High6.5fixed in 2.6.3 | High6.5 | 2.6.3 |
| Jul 122023 | Apache Airflow Improper Input Validation vulnerability CVE-2023-36543High6.5fixed in 2.6.3 | High6.5 | 2.6.3 |