Miggo Logo

CVE-2023-41267:
Apache HDFS Provider error message suggested

7.8

CVSS Score

Basic Information

EPSS Score
-
Published
9/14/2023
Updated
2/13/2025
KEV Status
No
Technology
TechnologyPython

Technical Details

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
apache-airflow-providers-apache-hdfspip< 4.1.14.1.1

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The vulnerability stemmed from incorrect package name references in error messages/documentation. The GitHub PR #33813 specifically mentions fixing the exception message's package name, which indicates the error message was generated in HDFSHook initialization when dependencies were missing. This function's error message was the primary vector for the misleading installation instruction, making it the clear vulnerable function. The confidence is high because the PR's context and commit message directly point to this correction in the HDFS provider's hook implementation.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

In t** *p**** *ir*low ***S Provi**r, v*rsions prior to *.*.*, * *o*um*nt*tion in*o point** us*rs to *n inst*ll in*orr**t pip p**k***. *s t*is p**k*** n*m* w*s un*l*im**, in t**ory, *n *tt**k*r *oul* *l*im t*is p**k*** *n* provi** *o** t**t woul* ** *

Reasoning

T** vuln*r**ility st*mm** *rom in*orr**t p**k*** n*m* r***r*n**s in *rror m*ss***s/*o*um*nt*tion. T** *it*u* PR #***** sp**i*i**lly m*ntions *ixin* t** *x**ption m*ss***'s p**k*** n*m*, w*i** in*i**t*s t** *rror m*ss*** w*s **n*r*t** in ***S*ook init