{"id":"GHSA-2rx4-9f5h-9gjf","summary":"Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configuration","details":"Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection.\n\nIn order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to change the connection object in this manner. Operators should upgrade to provider version 7.0.0 which has removed the vulnerability.","aliases":["CVE-2023-33234","PYSEC-2026-1143"],"modified":"2026-07-07T17:57:22.196888795Z","published":"2023-07-06T21:15:06Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-07-06T23:54:53Z","nvd_published_at":"2023-05-30T11:15:09Z","cwe_ids":["CWE-74"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-33234"},{"type":"PACKAGE","url":"https://github.com/apache/airflow"},{"type":"WEB","url":"https://lists.apache.org/thread/n1vpgl6h2qsdm52o9m2tx1oo86tl4gnq"}],"affected":[{"package":{"name":"apache-airflow-providers-cncf-kubernetes","ecosystem":"PyPI","purl":"pkg:pypi/apache-airflow-providers-cncf-kubernetes"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"7.0.0"}]}],"versions":["5.0.0","5.1.0","5.1.0rc1","5.1.0rc2","5.1.1","5.1.1rc1","5.2.0","5.2.0rc1","5.2.1","5.2.1rc1","5.2.2","5.2.2rc1","5.3.0","5.3.0rc1","6.0.0","6.0.0rc1","6.1.0","6.1.0rc1","6.2.0rc1","7.0.0rc2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-2rx4-9f5h-9gjf/GHSA-2rx4-9f5h-9gjf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}