Re: CVE-2023-25691: Apache Airflow Google Provider: Google Cloud Sql Provider Remote Command Execution

2023-02-23 Thread Jarek Potiuk
Also we would like to credit Xie Jianming of Caiji Sec Team (finder of the issue) On Thu, Feb 23, 2023 at 6:16 PM Jarek Potiuk wrote: > > Severity: moderate > > Description: > > Improper Input Validation vulnerability in Apache Software Foundation Apache > Airflow Google Provider.This issue

CVE-2023-25691: Apache Airflow Google Provider: Google Cloud Sql Provider Remote Command Execution

2023-02-23 Thread Jarek Potiuk
Severity: moderate Description: Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Google Provider.This issue affects Apache Airflow Google Provider: before 8.10.0. References: https://github.com/apache/airflow/pull/29497 https://airflow.apache.org/