« Volver al listado

Apache

Apache-airflow-providers-google: vulnerabilidades y CVE

Apache-airflow-providers-google tiene 5 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE5
Últimos 12 meses3
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-68868Media (6.5)0.60%—12 ago 2026
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped…
CVE-2026-49297Alta (8.1)0.99%—6 jul 2026
Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without…
CVE-2026-45361Alta (8.1)0.80%—25 may 2026
Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can…
CVE-2023-25692Alta (7.5)1.8%—24 feb 2023
Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0.
CVE-2023-25691Crítica (9.8)1.6%—24 feb 2023
Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1090.001 Internal Proxy1
  2. T1210 Exploitation of Remote Services1
  3. T1557 Adversary-in-the-Middle1
  4. T1565.002 Transmitted Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Apache