Exploit Report

Computer Security And Bug Information

CVE-2023-41267

CVECVE-2023-41267
CVE Title
Published Date2023-09-14T08:15Z
Modified Date2023-09-19T17:52Z
CWE TypeCWE-829
CVSS 3.xCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
DescriptionIn the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect pip package. As this package name was unclaimed, in theory, an attacker could claim this package and provide code that would be executed when this package was installed. The Airflow team has since taken ownership of the package (neutralizing the risk), and fixed the doc strings in version 4.1.1
References
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites.
Reference URLhttps://github.com/apache/airflow/pull/33813
Reference DescriptionMISC https://github.com/apache/airflow/pull/33813
Reference URLhttps://lists.apache.org/thread/ggthr5pn42bn6wcr25hxnykjzh4ntw7z
Reference DescriptionMISC https://lists.apache.org/thread/ggthr5pn42bn6wcr25hxnykjzh4ntw7z
Reference URLhttp://www.openwall.com/lists/oss-security/2023/09/14/3
Reference DescriptionMISC http://www.openwall.com/lists/oss-security/2023/09/14/3
TagsPatch
Sources NIST MITRE

This site's data is aggregated programmatically and provided "as is" without any representations or warranties, express or implied. Exploit.report is not affiliated with the The MITRE Corporation, U.S. Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), or US government in any way. CVE and the CVE logo are registered trademarks of The MITRE Corporation

© 2022 Exploit.Report | Data | Contact | Privacy Policy | Articles