Show filters
1,297 Total Results
Displaying 121-130 of 1,297
Sort by:
Attacker Value
Unknown
CVE-2023-41267
Disclosure Date: September 14, 2023 (last updated February 14, 2025)
In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect pip package. As this package name was unclaimed, in theory, an attacker could claim this package and provide code that would be executed when this package was installed. The Airflow team has since taken ownership of the package (neutralizing the risk), and fixed the doc strings in version 4.1.1
0
Attacker Value
Unknown
CVE-2023-40712
Disclosure Date: September 12, 2023 (last updated October 08, 2023)
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be masked in the UI.
Users are strongly advised to upgrade to version 2.7.1 or later which has removed the vulnerability.
0
Attacker Value
Unknown
CVE-2023-40611
Disclosure Date: September 12, 2023 (last updated February 14, 2025)
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.
Users should upgrade to version 2.7.1 or later which has removed the vulnerability.
0
Attacker Value
Unknown
CVE-2023-41593
Disclosure Date: September 11, 2023 (last updated October 08, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Dairy Farm Shop Management System Using PHP and MySQL v1.1 allow attackers to execute arbitrary web scripts and HTML via a crafted payload injected into the Category and Category Field parameters.
0
Attacker Value
Unknown
CVE-2023-41594
Disclosure Date: September 08, 2023 (last updated October 09, 2023)
Dairy Farm Shop Management System Using PHP and MySQL v1.1 was discovered to contain multiple SQL injection vulnerabilities in the Login function via the Username and Password parameters.
0
Attacker Value
Unknown
CVE-2015-2202
Disclosure Date: September 05, 2023 (last updated October 08, 2023)
Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS.
0
Attacker Value
Unknown
CVE-2015-2201
Disclosure Date: September 05, 2023 (last updated October 08, 2023)
Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by administrative users.
0
Attacker Value
Unknown
CVE-2015-1391
Disclosure Date: September 05, 2023 (last updated October 08, 2023)
Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism.
0
Attacker Value
Unknown
CVE-2015-1390
Disclosure Date: September 05, 2023 (last updated October 08, 2023)
Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator.
0
Attacker Value
Unknown
CVE-2023-40195
Disclosure Date: August 28, 2023 (last updated October 08, 2023)
Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflow Spark Provider.
When the Apache Spark provider is installed on an Airflow deployment, an Airflow user that is authorized to configure Spark hooks can effectively run arbitrary code on the Airflow node by pointing it at a malicious Spark server. Prior to version 4.1.3, this was not called out in the documentation explicitly, so it is possible that administrators provided authorizations to configure Spark hooks without taking this into account. We recommend administrators to review their configurations to make sure the authorization to configure Spark hooks is only provided to fully trusted users.
To view the warning in the docs please visit https://airflow.apache.org/docs/apache-airflow-providers-apache-spark/4.1.3/connections/spark.html
0