Loading HuntDB...

CVE-2023-41267

UNKNOWN
Published 2023-09-14T07:46:42.191Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2023-41267. We'll provide specific mitigation strategies based on your environment and risk profile.

No CVSS data available

Description

In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect pip package. As this package name was unclaimed, in theory, an attacker could claim this package and provide code that would be executed when this package was installed. The Airflow team has since taken ownership of the package (neutralizing the risk), and fixed the doc strings in version 4.1.1

Available Exploits

No exploits available for this CVE.

Related News

No news articles found for this CVE.

Affected Products

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

✓ GitHub Reviewed HIGH

Apache HDFS Provider error message suggested

GHSA-5hj9-m76g-xrc8

Advisory Details

In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect pip package. As this package name was unclaimed, in theory, an attacker could claim this package and provide code that would be executed when this package was installed. The Airflow team has since taken ownership of the package (neutralizing the risk), and fixed the doc strings in version 4.1.1

Affected Packages

PyPI apache-airflow-providers-apache-hdfs
ECOSYSTEM: ≥0 <4.1.1

CVSS Scoring

CVSS Score

7.5

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Advisory provided by GitHub Security Advisory Database. Published: September 14, 2023, Modified: February 13, 2025

References

Published: 2023-09-14T07:46:42.191Z
Last Modified: 2025-02-13T17:09:00.280Z
Copied to clipboard!