CVE-2023-34395

CVE-2023-34395: Apache Airflow ODBC Provider: Remote code execution vulnerability

Vendor Apache Software Foundation
Product Apache Airflow ODBC Provider
Weakness CWE-88
Published June 27, 2023
Last update October 7, 2024

CVSS base score

What the vulnerability does

Description

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Software Foundation Apache Airflow ODBC Provider. In OdbcHook, A privilege escalation vulnerability exists in a system due to controllable ODBC driver parameters that allow the loading of arbitrary dynamic-link libraries, resulting in command execution. Starting version 4.0.0 driver can be set only from the hook constructor. This issue affects Apache Airflow ODBC Provider: before 4.0.0.

Key dates

Disclosure timeline

June 27, 2023 CVE published
October 7, 2024 Record updated