CVE detail
CVE-2023-40272 — CVE-2023-40272
Published 2023-08-17 · Modified 2026-06-17 · Vendor apache · Product apache-airflow-providers-apache-spark · Source nvd
HIGH
severity
CVSS-derived band
0.0167
EPSS probability
exploitation probability, 30d
75.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection giving an opportunity to read files on the Airflow server.
It is recommended to upgrade to a version that is not affected.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References