cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2023-35798,https://securityvulnerability.io/vulnerability/CVE-2023-35798,Airflow Apache ODBC and MSSQL Providers Arbitrary File Read Vulnerability,"Input Validation vulnerability in Apache Software Foundation Apache Airflow ODBC Provider, Apache Software Foundation Apache Airflow MSSQL Provider.This vulnerability is considered low since it requires DAG code to use `get_sqlalchemy_connection` and someone with access to connection resources specifically updating the connection to exploit it. This issue affects Apache Airflow ODBC Provider: before 4.0.0; Apache Airflow MSSQL Provider: before 3.4.1. It is recommended to upgrade to a version that is not affected ",Apache,"Apache Airflow Odbc Provider,Apache Airflow Mssql Provider",4.3,MEDIUM,0.0013299999991431832,false,,false,false,false,,,false,false,,2023-06-27T12:15:00.000Z,0 CVE-2023-34395,https://securityvulnerability.io/vulnerability/CVE-2023-34395,Apache Airflow ODBC Provider: Remote code execution vulnerability,"A privilege escalation vulnerability exists within the Apache Airflow ODBC Provider due to unverified control over ODBC driver parameters. This flaw permits the loading of arbitrary dynamic-link libraries, which can lead to potential command execution by unauthorized users. Users of versions prior to 4.0.0 should take immediate action to upgrade and secure their systems.",Apache,Apache Airflow Odbc Provider,7.8,HIGH,0.0007200000109151006,false,,false,false,false,,,false,false,,2023-06-27T12:15:00.000Z,0