Skip to content
Apache AirflowPYSEC-2023-314

Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider.

Critical9.8CVE-2023-25693 · Published Feb 24, 2023 · updated Jun 29, 2026

Source advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 3.1.13.1.1
Details and references

Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
the CVSS score
Also known as
CVE-2023-25693, GHSA-j69x-v4wc-3fpf, PYSEC-2026-275

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Mar 152023Sensitive Information in Error Messages in Apache Airflow
CVE-2023-25695Medium5.3fixed in 2.5.2rc1
Jan 212023Command Injection in Apache Airflow and Apache Airflow MySQL Provider
CVE-2023-22884Critical9.8fixed in 2.5.1
Apr 72023Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider: before 2.3.2.
CVE-2023-28707High7.5fixed in 2.3.2
May 82023Apache Airflow vulnerable to stored Cross-site Scripting
CVE-2023-29247Medium5.4fixed in 2.6.0
May 82023Apache Airflow vulnerable to Privilege Context Switching Error
CVE-2023-25754Critical9.8fixed in 2.6.0b1
Nov 222022OS Command Injection in Apache Airflow
CVE-2022-40954Medium5.5fixed in 2.3.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.