Vulnerabilities > Apache > Airflow > 2.6.0

DATE CVE VULNERABILITY TITLE RISK
2023-07-12 CVE-2023-22888 Unspecified vulnerability in Apache Airflow
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to cause a service disruption by manipulating the run_id parameter.
network
low complexity
apache
6.5
2023-07-12 CVE-2023-35908 Incorrect Authorization vulnerability in Apache Airflow
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommended to upgrade to a version that is not affected
network
low complexity
apache CWE-863
6.5
2023-07-12 CVE-2023-36543 Unspecified vulnerability in Apache Airflow
Apache Airflow, versions before 2.6.3, has a vulnerability where an authenticated user can use crafted input to make the current request hang. It is recommended to upgrade to a version that is not affected
network
low complexity
apache
6.5
2023-06-19 CVE-2023-35005 Unspecified vulnerability in Apache Airflow 2.6.0
In Apache Airflow, some potentially sensitive values were being shown to the user in certain situations. This vulnerability is mitigated by the fact configuration is not shown in the UI by default (only if `[webserver] expose_config` is set to `non-sensitive-only`), and not all uncensored values are actually sentitive. This issue affects Apache Airflow: from 2.5.0 before 2.6.2.
network
low complexity
apache
6.5