Apache AirflowPYSEC-2023-314
Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider.
Critical9.8CVE-2023-25693 · Published Feb 24, 2023 · updated Jun 29, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | < 3.1.1 | 3.1.1 |
Details and references
Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the CVSS score
- Also known as
- CVE-2023-25693, GHSA-j69x-v4wc-3fpf, PYSEC-2026-275
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 152023 | Sensitive Information in Error Messages in Apache Airflow CVE-2023-25695Medium5.3fixed in 2.5.2rc1 | Medium5.3 | 2.5.2rc1 |
| Jan 212023 | Command Injection in Apache Airflow and Apache Airflow MySQL Provider CVE-2023-22884Critical9.8fixed in 2.5.1 | Critical9.8 | 2.5.1 |
| Apr 72023 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider: before 2.3.2. CVE-2023-28707High7.5fixed in 2.3.2 | High7.5 | 2.3.2 |
| May 82023 | Apache Airflow vulnerable to stored Cross-site Scripting CVE-2023-29247Medium5.4fixed in 2.6.0 | Medium5.4 | 2.6.0 |
| May 82023 | Apache Airflow vulnerable to Privilege Context Switching Error CVE-2023-25754Critical9.8fixed in 2.6.0b1 | Critical9.8 | 2.6.0b1 |
| Nov 222022 | OS Command Injection in Apache Airflow CVE-2022-40954Medium5.5fixed in 2.3.0 | Medium5.5 | 2.3.0 |