CVE-2023-34395: Apache Apache-Airflow-Providers-Odbc

High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Software Foundation Apache Airflow ODBC Provider. In OdbcHook, A privilege escalation vulnerability exists in a system due to controllable ODBC driver parameters that allow the loading of arbitrary dynamic-link libraries, resulting in command execution. Starting version 4.0.0 driver can be set only from the hook constructor. This issue affects Apache Airflow ODBC Provider: before 4.0.0.

Affected products

  • Apache Apache-Airflow-Providers-Odbc: before 4.0.0 (fixed in 4.0.0)

Published 2023-06-27. Last modified 2026-06-17.