Apache AirflowPYSEC-2023-3
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider: before 2.3.2.
High7.5CVE-2023-28707 · Published Apr 7, 2023 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | < 2.3.2 | 2.3.2 |
Changes since it was listed
| Date | Change |
|---|---|
| Sep 24 | Severity: Unrated to High |
Details and references
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider: before 2.3.2.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- NVD
- Also known as
- CVE-2023-28707, GHSA-85pf-r4c7-3j9r, PYSEC-2026-1136
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 152023 | Sensitive Information in Error Messages in Apache Airflow CVE-2023-25695Medium5.3fixed in 2.5.2rc1 | Medium5.3 | 2.5.2rc1 |
| May 82023 | Apache Airflow vulnerable to stored Cross-site Scripting CVE-2023-29247Medium5.4fixed in 2.6.0 | Medium5.4 | 2.6.0 |
| May 82023 | Apache Airflow vulnerable to Privilege Context Switching Error CVE-2023-25754Critical9.8fixed in 2.6.0b1 | Critical9.8 | 2.6.0b1 |
| Feb 242023 | Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. CVE-2023-25693Critical9.8fixed in 3.1.1 | Critical9.8 | 3.1.1 |
| Jun 192023 | Apache Airflow vulnerable to exposure of sensitive information CVE-2023-35005High6.5fixed in 2.6.2rc1 | High6.5 | 2.6.2rc1 |
| Jan 212023 | Command Injection in Apache Airflow and Apache Airflow MySQL Provider CVE-2023-22884Critical9.8fixed in 2.5.1 | Critical9.8 | 2.5.1 |