PT-2024-1305 · Apache · Apache Airflow

·

CVE-2023-50944

·

Published

2024-01-24

·

Updated

2026-02-20

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 2.8.1
Description The issue is related to a lack of authorization in Apache Airflow, allowing an authenticated user to access the source code of a DAG they do not have access to. This issue is considered low severity as it requires an authenticated user to exploit it.
Recommendations For Apache Airflow versions prior to 2.8.1, upgrade to version 2.8.1 to fix the issue. As a temporary workaround, consider restricting access to sensitive DAGs until the upgrade is applied.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00753
BIT-AIRFLOW-2023-50944
CVE-2023-50944
ECHO-BB04-FBDE-5D73
GHSA-VM5M-QMRX-FW8W
PYSEC-2024-14

Affected Products

Apache Airflow