PT-2026-95484 · Azkaban · Azkaban
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Azkaban versions prior to 4.0.1
Description
An authorization bypass exists in the
fetchSchedule action of the ScheduleServlet endpoint. Authenticated users can retrieve schedule configurations for any project by providing arbitrary project and flow identifiers. This allows unauthorized access to sensitive information, including execution times, cron expressions, flow parameters, and notification email lists.Recommendations
Update Azkaban to a version later than 4.0.0.
As a temporary mitigation, restrict access to the
ScheduleServlet endpoint to authorized administrators only.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Azkaban