Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advised to upgrade to `apache-airflow-providers-google` 22.0.0 or later.
oryginał ENCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HApache Airflow Providers Google
APPApache< 22.0.0
Powiązane podatności
Brak walidacji danych wejściowych w Apache Airflow Google Provider
Path Traversal w Apache Airflow Google Provider — zapis plików poza docelowym katalogiem
Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airf...
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team sco...
Apache Tomcat: Path Equivalence prowadzący do RCE i ujawnienia danych