cbcvebase.
CVE-2023-22884
published 2023-01-21

CVE-2023-22884: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software…

PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
11.08%
95.4th percentile
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Airflow MySQL Provider: before 4.0.0.

Affected

5 ranges
VendorProductVersion rangeFixed in
apacheairflow< 2.5.12.5.1
apacheapache-airflow-providers-mysql< 4.0.04.0.0
apacheapache-airflow-providers-mysql>= 0 < 4.0.04.0.0
apache_software_foundationapache_airflow< 2.5.12.5.1
apache_software_foundationapache_airflow_mysql_provider< 4.0.04.0.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.