CVE-2023-40272 is a high-severity vulnerability affecting Apache Airflow Spark Provider versions prior to 4.1.3, allowing attackers to read files on the Airflow server by injecting malicious parameters during connection establishment. With a CVSS score of 7.5 (HIGH), this vulnerability has a low attack complexity and requires no user interaction, posing a significant risk of information disclosure. Despite its severity, there is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.1.3CPE matchmatch criteria | cpe:2.3:a:apache:apache-airflow-providers-apache-spark:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.