CVE-2023-25691
published 2023-02-24CVE-2023-25691: Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0.
PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.58%
72.8th percentile
Improper Input Validation vulnerability in the Apache Airflow Google Provider.
This issue affects Apache Airflow Google Provider versions before 8.10.0.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache-airflow-providers-google | < 8.10.0 | 8.10.0 |
| apache | apache-airflow-providers-google | >= 0 < 8.10.0 | 8.10.0 |
| apache_software_foundation | apache_airflow_google_provider | < 8.10.0 | 8.10.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Airflow Google Provider Improper Input Validation vulnerability
ghsa·2023-02-24
CVE-2023-25691 [CRITICAL] CWE-20 Apache Airflow Google Provider Improper Input Validation vulnerability
Apache Airflow Google Provider Improper Input Validation vulnerability
Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0.
OSV
Apache Airflow Google Provider Improper Input Validation vulnerability
osv·2023-02-24
CVE-2023-25691 [CRITICAL] Apache Airflow Google Provider Improper Input Validation vulnerability
Apache Airflow Google Provider Improper Input Validation vulnerability
Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0.
No detection rules found.
No public exploits indexed.
2023-02-24
Published