Описание
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake.
This issue affects Apache Airflow Providers Snowflake: before 6.4.0.
Sanitation of table and stage parameters were added in CopyFromExternalStageToSnowflakeOperator to prevent SQL injection Users are recommended to upgrade to version 6.4.0, which fixes the issue.
Ссылки
- Issue TrackingPatch
- Mailing ListVendor Advisory
Уязвимые конфигурации
EPSS
9.8 Critical
CVSS3
Дефекты
Связанные уязвимости
Apache Airflow Providers Snowflake package allows for Special Element Injection via CopyFromExternalStageToSnowflakeOperator
Уязвимость функции CopyFromExternalStageToSnowflakeOperator() пакета интеграции с облачной платформой данных Apache Airflow Providers Snowflake, позволяющая нарушителю выполнить произвольный код
EPSS
9.8 Critical
CVSS3