Apache Airflow Teradata 提供商中的计算集群示例 DAG 将所有 DAG 参数均声明为不受约束的自由文本,并直接将这些参数模板化地传入计算集群操作符。这些操作符会将这些值插值到 Teradata DDL 语句中。因此,任何有权触发该 DAG 的用户(其信任级别低于 DAG 作者,且无需拥有自身的 Teradata 凭据)均可提供 SQL 片段,这些片段将以任务运行时的连接身份执行。此外,由于连接 ID 本身也是一个自由文本参数,用户还可以将任务重定向到部署环境中定义的任何其他连接。只有运行此示
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Airflow Teradata provider | 0 ~ 3.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102496 | Apache XMLSchema: Denial of service through deeply nested schema structures | |
| CVE-2026-91012 | Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalatio | |
| CVE-2026-91048 | Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege esc | |
| CVE-2026-91085 | Apache Karaf: config:install missing ACL entry allows privilege escalation to admin | |
| CVE-2026-92142 | Apache Karaf: Authorization bypass in JMX MBean lifecycle operations | |
| CVE-2026-81914 | Apache Airflow Google provider: Google Drive query injection via unescaped file and folder | |
| CVE-2026-81862 | Apache Airflow Teradata provider: Teradata transfer operators embed cloud storage credenti | |
| CVE-2026-81930 | Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer toke | |
| CVE-2026-102495 | Apache XMLSchema: Denial of service through unbounded recursion when resolving schema impo | |
| CVE-2026-97395 | Apache Polaris: Allows authorized table writers to redirect server-side Iceberg FileIO req | |
| CVE-2026-102497 | Apache XMLSchema: Denial of service through cyclic schema definitions in the schema walker | |
| CVE-2026-66083 | Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasourc | |
| CVE-2026-82804 | Apache DolphinScheduler: Command Injection in the Alert Script Plugin | |
| CVE-2026-81569 | Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized | |
| CVE-2026-78214 | Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths | |
| CVE-2026-71899 | Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to | |
| CVE-2026-71898 | Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute | |
| CVE-2026-71897 | Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and ba |
No comments yet