Impact
Apache Airflow's Google provider builds Google Drive search expressions by interpolating file and folder names directly into single-quoted strings without escaping quote characters. A name containing an apostrophe terminates the literal early and allows an adversary to append arbitrary clauses to the query, effectively performing a logical injection. This flaw was identified as CWE‑943 and can cause the provider to resolve uploads or downloads to attacker‑controlled folders or files, enabling the execution of unwanted data transfers and potentially exposing or replacing sensitive content.
Affected Systems
The vulnerability affects deployments of the Apache Airflow Google provider through older provider versions before 22.6.0 that send externally sourced file or folder names to the Google Drive hook. Commonly impacted scenarios include wildcard "gcs_to_gdrive" transfers where the source bucket is writable by principals other than the DAG author.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in CISA's KEV catalog, indicating a low to moderate probability of discovery and exploitation. However, exploitation requires the ability to create or modify objects in the source bucket; this is often granted to external data producers or ingest‑only service accounts. The attack vector is therefore an internal or coordinated external actor with write access to the bucket, which appends a maliciously crafted object name. If successful, the hacker can steer uploads to a chosen folder or cause downloads to return attacker‑placed files, leading to unauthorized data access or manipulation.
OpenCVE Enrichment