Vulnerabilities > Apache > Airflow > 2.6.1

DATE CVE VULNERABILITY TITLE RISK
2023-07-12 CVE-2023-35908 Incorrect Authorization vulnerability in Apache Airflow
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommended to upgrade to a version that is not affected
network
low complexity
apache CWE-863
6.5
2023-07-12 CVE-2023-36543 Unspecified vulnerability in Apache Airflow
Apache Airflow, versions before 2.6.3, has a vulnerability where an authenticated user can use crafted input to make the current request hang. It is recommended to upgrade to a version that is not affected
network
low complexity
apache
6.5