PT-2026-96119 · Apache · Apache Airflow
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Airflow versions prior to 3.3.2
Description
The
/assets/events API endpoint fails to restrict asset events to the Dags that the caller is authorized to read. Authenticated users with asset-read access can enumerate asset events for Dags they lack permission to view, exposing the source Dag ID, task ID, run ID, and event timestamps. Additionally, the absence of a filter in the count query allows the total entries and pagination features to disclose the existence of hidden Dags. This issue occurs in deployments utilizing per-Dag access control to separate teams or tenants.Recommendations
Upgrade to apache-airflow version 3.3.2 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow