logo

Database

Lack of data validation In apache-airflow-providers-apache-spark

Description

Apache Airflow Spark Provider vulnerable to improper input validation Apache Software Foundation Apache Airflow Spark Provider before 4.0.1 is vulnerable to improper input validation because the host and schema of JDBC Hook can contain / and ? which is used to denote the end of the field.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions