Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2rx4-9f5h-9gjf

Опубликовано: 06 июл. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configuration

Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection.

In order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to change the connection object in this manner. Operators should upgrade to provider version 7.0.0 which has removed the vulnerability.

Пакеты

Наименование

apache-airflow-providers-cncf-kubernetes

pip
Затронутые версииВерсия исправления

>= 5.0.0, < 7.0.0

7.0.0

EPSS

Процентиль: 52%
0.00289
Низкий

7.2 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 7.2
nvd
больше 2 лет назад

Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. In order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to change the connection object in this manner.  Operators should upgrade to provider version 7.0.0 which has removed the vulnerability.

CVSS3: 7.2
fstec
больше 2 лет назад

Уязвимость сетевого программного средства Apache Airflow CNCF Kubernetes Provider, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 52%
0.00289
Низкий

7.2 High

CVSS3

Дефекты

CWE-74