PT-2024-1305 · Apache · Apache Airflow
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Apache Airflow versions prior to 2.8.1
Description
The issue is related to a lack of authorization in Apache Airflow, allowing an authenticated user to access the source code of a DAG they do not have access to. This issue is considered low severity as it requires an authenticated user to exploit it.
Recommendations
For Apache Airflow versions prior to 2.8.1, upgrade to version 2.8.1 to fix the issue. As a temporary workaround, consider restricting access to sensitive DAGs until the upgrade is applied.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow