Description
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Airflow MySQL Provider: before 4.0.0.

Published: 2023-01-21
Score: 9.8 Critical
EPSS: 78.1% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-c732-xvv8-g94c Command Injection in Apache Airflow and Apache Airflow MySQL Provider
History

Mon, 31 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Apache Airflow Apache-airflow-providers-mysql
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-03-31T14:53:54.464Z

Reserved: 2023-01-09T19:22:17.207Z

Link: CVE-2023-22884

cve-icon Vulnrichment

Updated: 2024-08-02T10:20:31.113Z

cve-icon NVD

Status : Modified

Published: 2023-01-21T14:15:10.280

Modified: 2025-03-31T15:15:39.513

Link: CVE-2023-22884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses