apache-airflow-providers-cncf-kubernetes vulnerabilities
CVEs whose affected-version data names the apache-airflow-providers-cncf-kubernetes package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2023-51702Medium· 6.5Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in met…
Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in met…
▾ Sunlitapache · airflowEPSS 0.39%via NVD
CVE-2023-33234High· 7.2Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. In order to exploit this weakness, a user would already need elevated permi…
Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. In order to exploit this weakness, a user would already need elevated permi…
▾ Twilightapache · apache-airflow-providers-cncf-kubernetesEPSS 1.5%via NVD