SCA: security update for apache-airflow (GHSA-45r6-j3cc-6mxx)

medium Tenable Self-Hosted Container Security Plugin ID 409968

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability
in Apache Airflow Spark Provider, Apache Airflow allows an attacker to read arbtrary files in the task
execution context, without write access to DAG files. This issue affects Spark Provider versions prior to
4.0.0. It also impacts any Apache Airflow versions prior to 2.3.0 in case Spark Provider is installed
(Spark Provider 4.0.0 can only be installed for Airflow 2.3.0+). Note that you need to manually install
the Spark Provider version 4.0.0 in order to get rid of the vulnerability on top of Airflow 2.3.0+ version
that has lower version of the Spark Provider installed). (CVE-2022-40954)

See Also

https://github.com/advisories/GHSA-45r6-j3cc-6mxx

Plugin Details

Severity: Medium

ID: 409968

Version: Revision 1.9

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:N

CVSS Score Source: CVE-2022-40954

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 11/22/2022

Vulnerability Publication Date: 11/22/2022

Reference Information

CVE: CVE-2022-40954

cwe: CWE-78