Skip to content
Apache AirflowPYSEC-2023-136

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.

High7.5CVE-2023-39553 · Published Aug 11, 2023 · updated Jul 7, 2026

Source advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.4.32.4.3

Changes since it was listed

DateChange
Sep 24Severity: Unrated to High
Details and references

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider. Apache Airflow Drill Provider is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection with DrillHook giving an opportunity to read files on the Airflow server. This issue affects Apache Airflow Drill Provider: before 2.4.3. It is recommended to upgrade to a version that is not affected.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
NVD
Also known as
CVE-2023-39553, GHSA-mq4v-6vg4-796c, PYSEC-2026-1137

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Aug 52023Apache Airflow Execution with Unnecessary Privileges
CVE-2023-39508High8.8fixed in 2.6.0b1
Aug 232023Apache Airflow missing Certificate Validation
CVE-2023-39441Medium5.9fixed in 2.7.0
Aug 232023Apache Airflow Session Fixation vulnerability
CVE-2023-40273High8.0fixed in 2.7.0rc2
Aug 232023Apache Airflow denial of service vulnerability
CVE-2023-37379High8.1fixed in 2.7.0b1
Jul 122023Apache Airflow Incorrect Authorization vulnerability
CVE-2023-35908High6.5fixed in 2.6.3
Jul 122023Apache Airflow Improper Input Validation vulnerability
CVE-2023-36543High6.5fixed in 2.6.3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.