Vulnerabilities > Apache > Airflow > 2.0.0

DATE CVE VULNERABILITY TITLE RISK
2023-09-12 CVE-2023-40611 Incorrect Authorization vulnerability in Apache Airflow
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes.
network
low complexity
apache CWE-863
4.3
2023-09-12 CVE-2023-40712 Information Exposure vulnerability in Apache Airflow
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be masked in the UI. Users are strongly advised to upgrade to version 2.7.1 or later which has removed the vulnerability.
network
low complexity
apache CWE-200
6.5
2023-08-23 CVE-2023-37379 Unspecified vulnerability in Apache Airflow
Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection edit privileges.
network
low complexity
apache
8.1
2023-08-23 CVE-2023-39441 Improper Certificate Validation vulnerability in Apache Airflow
Apache Airflow SMTP Provider before 1.3.0, Apache Airflow IMAP Provider before 3.3.0, and Apache Airflow before 2.7.0 are affected by the Validation of OpenSSL Certificate vulnerability. The default SSL context with SSL library did not check a server's X.509 certificate.  Instead, the code accepted any certificate, which could result in the disclosure of mail server credentials or mail contents when the client connects to an attacker in a MITM position. Users are strongly advised to upgrade to Apache Airflow version 2.7.0 or newer, Apache Airflow IMAP Provider version 3.3.0 or newer, and Apache Airflow SMTP Provider version 1.3.0 or newer to mitigate the risk associated with this vulnerability
network
high complexity
apache CWE-295
5.9
2023-08-23 CVE-2023-40273 Session Fixation vulnerability in Apache Airflow
The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the password of the user has been reset by the admin - up until the expiry of the session of the user.
network
low complexity
apache CWE-384
8.0
2023-08-05 CVE-2023-39508 Unspecified vulnerability in Apache Airflow
Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Airflow.The "Run Task" feature enables authenticated user to bypass some of the restrictions put in place.
network
low complexity
apache
8.8
2023-07-12 CVE-2022-46651 Unspecified vulnerability in Apache Airflow
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Connection edit view.
network
low complexity
apache
6.5
2023-07-12 CVE-2023-22887 Path Traversal vulnerability in Apache Airflow
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to perform unauthorized file access outside the intended directory structure by manipulating the run_id parameter.
network
low complexity
apache CWE-22
6.5
2023-07-12 CVE-2023-22888 Unspecified vulnerability in Apache Airflow
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to cause a service disruption by manipulating the run_id parameter.
network
low complexity
apache
6.5
2023-07-12 CVE-2023-35908 Incorrect Authorization vulnerability in Apache Airflow
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommended to upgrade to a version that is not affected
network
low complexity
apache CWE-863
6.5