Vulnerabilities > Apache > Airflow > 2.3.1

DATE CVE VULNERABILITY TITLE RISK
2023-07-12 CVE-2023-35908 Incorrect Authorization vulnerability in Apache Airflow
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommended to upgrade to a version that is not affected
network
low complexity
apache CWE-863
6.5
2023-07-12 CVE-2023-36543 Unspecified vulnerability in Apache Airflow
Apache Airflow, versions before 2.6.3, has a vulnerability where an authenticated user can use crafted input to make the current request hang. It is recommended to upgrade to a version that is not affected
network
low complexity
apache
6.5
2023-05-08 CVE-2023-25754 Unspecified vulnerability in Apache Airflow
Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0.
network
low complexity
apache
critical
9.8
2023-05-08 CVE-2023-29247 Cross-site Scripting vulnerability in Apache Airflow
Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0.
network
low complexity
apache CWE-79
5.4
2023-03-15 CVE-2023-25695 Information Exposure Through an Error Message vulnerability in Apache Airflow
Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2.
network
low complexity
apache CWE-209
5.3
2023-01-21 CVE-2023-22884 Command Injection vulnerability in Apache Airflow
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Airflow MySQL Provider: before 4.0.0.
network
low complexity
apache CWE-77
critical
9.8
2022-11-15 CVE-2022-45402 Open Redirect vulnerability in Apache Airflow
In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint.
network
low complexity
apache CWE-601
6.1
2022-11-14 CVE-2022-40127 Code Injection vulnerability in Apache Airflow
A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter.
network
low complexity
apache CWE-94
8.8
2022-11-02 CVE-2022-43982 Cross-site Scripting vulnerability in Apache Airflow
In Apache Airflow versions prior to 2.4.2, the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument.
network
low complexity
apache CWE-79
6.1
2022-11-02 CVE-2022-43985 Open Redirect vulnerability in Apache Airflow
In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint.
network
low complexity
apache CWE-601
6.1