The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade apache-airflow-providers-google to version 22.6.0rc1 or higher.
apache-airflow-providers-google is a Provider for Apache Airflow. Implements apache-airflow-providers-google package
Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Data Query Logic via GoogleDriveHook in drive.py, where folder names, file names, and folder IDs are interpolated directly into Google Drive q= query string literals without escaping. The Drive query language uses single quotes to delimit string literals and requires backslash-escaping of ' and \, but neither _ensure_folders_exists nor get_file_id applied any escaping before constructing expressions such as name='<folder>' and '<parent>' in parents. An attacker, or ordinary input containing a single quote, can cause the composed query expression to be malformed, resulting in the search not matching the intended target and potentially returning unintended results or bypassing expected access controls. Because object names routinely arrive from bucket listings rather than being written by hand, a quote in a name is ordinary input rather than a special case.