GHSA-2rx4-9f5h-9gjf

Suggest an improvement
Source
https://github.com/advisories/GHSA-2rx4-9f5h-9gjf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-2rx4-9f5h-9gjf/GHSA-2rx4-9f5h-9gjf.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-2rx4-9f5h-9gjf
Aliases
  • CVE-2023-33234
Published
2023-07-06T21:15:06Z
Modified
2023-11-10T05:37:16.272259Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configuration
Details

Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection.

In order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to change the connection object in this manner. Operators should upgrade to provider version 7.0.0 which has removed the vulnerability.

Database specific
{
    "nvd_published_at": "2023-05-30T11:15:09Z",
    "cwe_ids": [
        "CWE-74"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2023-07-06T23:54:53Z"
}
References

Affected packages

PyPI / apache-airflow-providers-cncf-kubernetes

Package

Name
apache-airflow-providers-cncf-kubernetes
View open source insights on deps.dev
Purl
pkg:pypi/apache-airflow-providers-cncf-kubernetes

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0
Fixed
7.0.0

Affected versions

5.*

5.0.0
5.1.0rc1
5.1.0rc2
5.1.0
5.1.1rc1
5.1.1
5.2.0rc1
5.2.0
5.2.1rc1
5.2.1
5.2.2rc1
5.2.2
5.3.0rc1
5.3.0

6.*

6.0.0rc1
6.0.0
6.1.0rc1
6.1.0
6.2.0rc1

7.*

7.0.0rc2