Impact
A flaw in the Apache Airflow Apache Kafka provider allows a user with permission to edit Airflow connections to resolve dotted‑path strings in a Kafka connection’s ‘extra’ field into Python callables via import_string, without an allowlist. The resulting callables are passed to the confluent‑kafka client library, which executes them in the scheduler process. The flaw enables arbitrary code execution in the Airflow control plane, a privilege that normally belongs only to downstream workers.
Affected Systems
The vulnerability affects Apache Airflow Apache Kafka provider versions 1.15.0 up to, but not including, 2.0.0. Deployments that enable the Kafka event producer (dag_run_events_enabled or task_instance_events_enabled) are at risk; these options are disabled by default. Plain Kafka brokers and Amazon MSK are exposed. Users is recommended to upgrade to apache‑airflow‑providers‑apache‑kafka 2.0.0 or later, which adds an allowlist configuration option for connection‑string callbacks.
Risk and Exploitability
The vulnerability provides a high‑severity attack surface: a malicious actor who can edit connection configurations can run arbitrary code on the scheduler. The CVSS score of 8.8 indicates a high likelihood of critical impact, while the EPSS score of <1% suggests a low probability of exploitation in the immediate future. The weakness is classified as CWE‑470 (Use of Hard‑coded Buffer or Resource). The attack vector is likely based on privileged connection management in Airflow. The vulnerability is not listed in CISA KEV. The available fix is a software update to provider 2.0.0 or later, which introduces an allowlist for callbacks.
OpenCVE Enrichment