Bug 2238983 (CVE-2023-41267)

Summary: CVE-2023-41267 apache-airflow: Apache HDFS Provider error message suggested installation of incorrect pip package
Product: [Other] Security Response Reporter: Chess Hazlett <chazlett>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2238984    
Bug Blocks:    

Description Chess Hazlett 2023-09-14 16:18:12 UTC
In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentationĀ info pointed users to an install incorrect pip package. As this package name was unclaimed, in theory, an attacker could claim this package and provide code that would be executed when this package was installed. The Airflow team has since taken ownership of the package (neutralizing the risk), and fixed the doc strings in version 4.1.1


https://github.com/apache/airflow/pull/33813
https://lists.apache.org/thread/ggthr5pn42bn6wcr25hxnykjzh4ntw7z

Comment 1 Chess Hazlett 2023-09-14 16:18:25 UTC
Created golang-cloud-google tracking bugs for this issue:

Affects: fedora-38 [bug 2238984]