{"id":"CVE-2023-28707","aliases":["GHSA-85pf-r4c7-3j9r","PYSEC-2023-3","PYSEC-2026-1136"],"title":"Apache Airflow Drill Provider vulnerable to improper input validation ","summary":"Apache Airflow Drill Provider vulnerable to improper input validation ","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","vendor":"apache-airflow-providers-apache-drill","product":"apache-airflow-providers-apache-drill","ecosystem":"pip","affected":["apache-airflow-providers-apache-drill < 2.3.2"],"patched":["apache-airflow-providers-apache-drill 2.3.2"],"published":"2023-04-07","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-85pf-r4c7-3j9r","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-28707"},{"url":"https://github.com/apache/airflow/pull/30215"},{"url":"https://github.com/apache/airflow/commit/63d9b24aad0b4b9397682ddac1ea5824354789b3"},{"url":"https://github.com/apache/airflow"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2023-3.yaml"},{"url":"https://lists.apache.org/thread/dfoj7q1nd0vhhsl8fjg63z4j6mfmdxtk"},{"url":"https://www.openwall.com/lists/oss-security/2023/04/07/1"},{"url":"http://www.openwall.com/lists/oss-security/2023/04/07/1"}],"tags":["osv","pip"],"epss":0.02062,"epssPercentile":0.80505,"ingestedAt":"2026-07-08T18:25:47.304Z","slug":"CVE-2023-28707","body":"## Overview\n\nApache Software Foundation's Apache Airflow Drill Provider before 2.3.2 is vulnerable to improper input validation because the host passed in drill connection is not sanitized.\n\n## Affected packages\n\n- `apache-airflow-providers-apache-drill < 2.3.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `apache-airflow-providers-apache-drill 2.3.2`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}