Skip to content
Apache AirflowPYSEC-2023-3

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider: before 2.3.2.

High7.5CVE-2023-28707 · Published Apr 7, 2023 · updated Jul 7, 2026

Source advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.3.22.3.2

Changes since it was listed

DateChange
Sep 24Severity: Unrated to High
Details and references

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider: before 2.3.2.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
NVD
Also known as
CVE-2023-28707, GHSA-85pf-r4c7-3j9r, PYSEC-2026-1136

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Mar 152023Sensitive Information in Error Messages in Apache Airflow
CVE-2023-25695Medium5.3fixed in 2.5.2rc1
May 82023Apache Airflow vulnerable to stored Cross-site Scripting
CVE-2023-29247Medium5.4fixed in 2.6.0
May 82023Apache Airflow vulnerable to Privilege Context Switching Error
CVE-2023-25754Critical9.8fixed in 2.6.0b1
Feb 242023Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider.
CVE-2023-25693Critical9.8fixed in 3.1.1
Jun 192023Apache Airflow vulnerable to exposure of sensitive information
CVE-2023-35005High6.5fixed in 2.6.2rc1
Jan 212023Command Injection in Apache Airflow and Apache Airflow MySQL Provider
CVE-2023-22884Critical9.8fixed in 2.5.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.