Vulnerabilities > CVE-2023-35908 - Incorrect Authorization vulnerability in Apache Airflow

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
apache
CWE-863

Summary

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommended to upgrade to a version that is not affected

Vulnerable Configurations

Part Description Count
Application
Apache
108

Common Weakness Enumeration (CWE)