Apache Airflow是美国阿帕奇(Apache)基金会的一套具有创建、管理和监控工作流程功能的开源平台。该平台具有可扩展和动态监控等特点。 Apache Airflow Samba provider存在路径遍历漏洞,该漏洞源于GCSToSambaOperator将GCS对象名称连接到SMB目标路径时未进行包含检查,因此名为../段的对象名称解析到配置的destination_path之外的写入路径,能够将对象写入源GCS存储桶的攻击者可以在操作运行时将文件写入Samba目标上的任意位置。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Airflow Samba provider | < 4.12.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Airflow Samba provider | 0 ~ 4.12.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34905 | Apache Answer: Unlisted Questions Accessible via Direct API Access | |
| CVE-2026-34033 | Apache Answer: HTML Content Injection in Email | |
| CVE-2026-34031 | Apache Answer: The custom avatar was not properly validated | |
| CVE-2026-33582 | Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory error | |
| CVE-2026-25699 | Apache Answer: Authorization Bypass in Timeline API | |
| CVE-2026-25688 | Apache Answer: XSS in AI Answer Rendering |
No comments yet