CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.8. It affects Apache.
CVE
CVE-2023-22886
Severity
HIGH
CVSS
8.8
EPSS
1.52%
Apache
Original NVD Description
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider. Airflow JDBC Provider Connection’s [Connection URL] parameters had no restrictions, which made it possible to implement RCE attacks via different type JDBC drivers, obtain airflow server permission. This issue affects Apache Airflow JDBC Provider: before 4.0.0.
Related CVEs
Other vulnerabilities affecting the same vendor(s)