CVE-2023-35798

MEDIUM

Apache Airflow ODBC Provider < 4.0.0 and MSSQL Provider < 3.4.1 - Improper Input Validation in get_sqlalchemy_connection

Title source: llm
STIX 2.1

Description

Input Validation vulnerability in Apache Software Foundation Apache Airflow ODBC Provider, Apache Software Foundation Apache Airflow MSSQL Provider.This vulnerability is considered low since it requires DAG code to use `get_sqlalchemy_connection` and someone with access to connection resources specifically updating the connection to exploit it. This issue affects Apache Airflow ODBC Provider: before 4.0.0; Apache Airflow MSSQL Provider: before 3.4.1. It is recommended to upgrade to a version that is not affected

References (2)

Core 2
Core References
Patch, Vendor Advisory patch
https://github.com/apache/airflow/pull/31984
Mailing List, Vendor Advisory vendor-advisory
https://lists.apache.org/thread/951rb9m7wwox5p30tdvcfjxq8j1mp4pj

Scores

CVSS v3 4.3
EPSS 0.0014
EPSS Percentile 33.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (4)
apache/apache-airflow-providers-microsoft-mssql < 3.4.1
apache/apache-airflow-providers-odbc < 4.0.0
pypi/apache-airflow-providers-microsoft-mssql 0 - 3.4.1PyPI
pypi/apache-airflow-providers-odbc 0 - 4.0.0PyPI
Published Jun 27, 2023
Tracked Since Feb 18, 2026