CVE-2023-41267

CVE-2023-41267: Apache HDFS Provider error message suggested installation of incorrect pip package

Vendor Apache Software Foundation
Product Apache Airflow HDFS Provider
Weakness CWE-829 · Inclusion from untrusted sphere
Published September 14, 2023
Last update February 13, 2025

CVSS base score

What the vulnerability does

Description

In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect pip package. As this package name was unclaimed, in theory, an attacker could claim this package and provide code that would be executed when this package was installed. The Airflow team has since taken ownership of the package (neutralizing the risk), and fixed the doc strings in version 4.1.1

Key dates

Disclosure timeline

September 14, 2023 CVE published
February 13, 2025 Record updated