Junglewise Threat Intelligence

CVE-2023-25693: Apache Airflow Sqoop Provider improper input validation

CVE-2023-25693 · Severity: critical · CVSS 9.8 · Published 2023-02-24

Technologies: apache-airflow (PyPI). Vendors: PyPI, Apache, Apache Software Foundation.

Executive brief

The Apache Airflow Sqoop Provider, a tool used to transfer data between Apache Hadoop and structured datastores, contains a critical security flaw. This vulnerability allows an attacker to bypass security checks by providing improperly formatted input. If exploited, this could lead to unauthorized access to sensitive data or complete control over the data transfer process, potentially disrupting business operations and compromising customer information.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Apache Airflow Sqoop Provider prior to version 3.1.1. The flaw is related to how parameters like 'libjars' are handled within the Sqoop Hook and Operator. A remote attacker can exploit this by providing specially crafted input that is not correctly validated before being processed by the underlying Hadoop argument-parsing system. This can lead to unauthorized command execution or data access with the privileges of the Airflow worker. The issue was addressed in version 3.1.1 by moving the 'libjars' parameter from connection configuration to Hook parameters to ensure better control and validation.

Affected products

  • Apache apache-airflow-providers-apache-sqoop < 3.1.1

Timeline

  • 2023-02-12: other: Pull request to fix the issue submitted
  • 2023-02-24: advisory: Initial disclosure and GHSA/CVE publication
  • 2023-02-24: patched: Version 3.1.1 released

References

Related threats