{"id":"CVE-2023-33234","title":"Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection.\n\nIn order to exploit this weakness, a user would already need elevated permi…","summary":"Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection.\n\nIn order to exploit this weakness, a user would already need elevated permi…","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-74"],"vendor":"apache","product":"apache-airflow-providers-cncf-kubernetes","affected":["apache-airflow-providers-cncf-kubernetes >= 5.0.0, < 7.0.0"],"patched":["apache-airflow-providers-cncf-kubernetes 7.0.0"],"published":"2023-05-30","updated":"2026-07-02","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-33234","references":[{"url":"https://lists.apache.org/thread/n1vpgl6h2qsdm52o9m2tx1oo86tl4gnq","label":"security@apache.org"},{"url":"https://lists.apache.org/thread/n1vpgl6h2qsdm52o9m2tx1oo86tl4gnq","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01544,"epssPercentile":0.7389,"ingestedAt":"2026-07-02T17:40:39.259Z","slug":"CVE-2023-33234","body":"## Overview\n\nArbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection.\n\nIn order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to change the connection object in this manner.  Operators should upgrade to provider version 7.0.0 which has removed the vulnerability.\n\n\n\n## Affected\n\n- `apache-airflow-providers-cncf-kubernetes >= 5.0.0, < 7.0.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `apache-airflow-providers-cncf-kubernetes 7.0.0`","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}