漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache Airflow Sqoop Provider: Airflow Sqoop Provider RCE Vulnerability
Vulnerability Description
Apache Airflow Sqoop Provider, versions before 4.0.0, is affected by a vulnerability that allows an attacker pass parameters with the connections, which makes it possible to implement RCE attacks via ‘sqoop import --connect’, obtain airflow server permissions, etc. The attacker needs to be logged in and have authorization (permissions) to create/edit connections. It is recommended to upgrade to a version that is not affected. This issue was reported independently by happyhacking-k, And Xie Jianming and LiuHui of Caiji Sec Team also reported it.
CVSS Information
N/A
Vulnerability Type
输入验证不恰当
Vulnerability Title
Apache Airflow 输入验证错误漏洞
Vulnerability Description
Apache Airflow是美国阿帕奇(Apache)基金会的一套用于创建、管理和监控工作流程的开源平台。该平台具有可扩展和动态监控等特点。 Apache Airflow Sqoop Provider 4.0.0之前版本存在输入验证错误漏洞,该漏洞源于允许攻击者通过连接传递参数实施远程代码执行攻击,从而获取服务器权限等。
CVSS Information
N/A
Vulnerability Type
N/A