Vulnerabilities > Apache > Airflow Spark Provider

DATE CVE VULNERABILITY TITLE RISK
2023-08-28 CVE-2023-40195 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Airflow Spark Provider
Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflow Spark Provider. When the Apache Spark provider is installed on an Airflow deployment, an Airflow user that is authorized to configure Spark hooks can effectively run arbitrary code on the Airflow node by pointing it at a malicious Spark server.
network
low complexity
apache CWE-829
8.8