Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
High
CVE-2023-34395 CVSS:7.8
Apache Airflow ODBC Provider could allow a local authenticated attacker to gain elevated privileges on the system, caused by a flaw with controllable ODBC driver parameters. By using a specially crafted .DLL file, an authenticated attacker could exploit this vulnerability to gain elevated privileges and execute arbitrary code.
CVE-2023-22886 CVSS:8.8
Apache Airflow JDBC Provider could allow a remote authenticated attacker to execute arbitrary code on the system, caused by improper input validation. By sending a specially crafted request using Connection URL parameters, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVE-2023-35798 CVSS:4.3
Apache Airflow ODBC Provider and MSSQL Provider could allow a remote authenticated attacker to obtain sensitive information, caused by improper input validation. By sending a specially crafted request using get_sqlalchemy_connection, an attacker could exploit this vulnerability to read arbitrary files, and use this information to launch further attacks against the affected system.
Apache
Upgrade to the latest version of Apache Airflow ODBC Provider, available from the Apache Airflow Website.