In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentationĀ info pointed users to an install incorrect pip package. As this package name was unclaimed, in theory, an attacker could claim this package and provide code that would be executed when this package was installed. The Airflow team has since taken ownership of the package (neutralizing the risk), and fixed the doc strings in version 4.1.1
History

Wed, 25 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2023-09-14T07:46:42.191Z

Updated: 2024-09-25T18:23:52.898Z

Reserved: 2023-08-27T21:27:41.472Z

Link: CVE-2023-41267

cve-icon Vulnrichment

Updated: 2024-08-02T18:54:05.175Z

cve-icon NVD

Status : Analyzed

Published: 2023-09-14T08:15:07.967

Modified: 2023-09-19T17:52:38.127

Link: CVE-2023-41267

cve-icon Redhat

No data.