Vulnerabilities > Apache > Airflow

DATE CVE VULNERABILITY TITLE RISK
2023-10-23 CVE-2023-46288 Unspecified vulnerability in Apache Airflow
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.4.0 to 2.7.0. Sensitive configuration information has been exposed to authenticated users with the ability to read configuration via Airflow REST API for configuration even when the expose_config option is set to non-sensitive-only.
network
low complexity
apache
4.3
2023-10-14 CVE-2023-42663 Unspecified vulnerability in Apache Airflow
Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs. Users of Apache Airflow are advised to upgrade to version 2.7.2 or newer to mitigate the risk associated with this vulnerability.
network
low complexity
apache
6.5
2023-10-14 CVE-2023-42780 Information Exposure vulnerability in Apache Airflow
Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that allows authenticated users of Airflow to list warnings for all DAGs, even if the user had no permission to see those DAGs.
network
low complexity
apache CWE-200
6.5
2023-10-14 CVE-2023-42792 Exposure of Resource to Wrong Sphere vulnerability in Apache Airflow
Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could give the user write access to various DAG resources for DAGs that the user had no access to, thus, enabling the user to clear DAGs they shouldn't. Users of Apache Airflow are strongly advised to upgrade to version 2.7.2 or newer to mitigate the risk associated with this vulnerability.
network
low complexity
apache CWE-668
6.5
2023-10-14 CVE-2023-45348 Unspecified vulnerability in Apache Airflow 2.7.0/2.7.1
Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the "expose_config" option is set to "non-sensitive-only".
network
low complexity
apache
4.3
2023-09-12 CVE-2023-40611 Incorrect Authorization vulnerability in Apache Airflow
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes.
network
low complexity
apache CWE-863
4.3
2023-09-12 CVE-2023-40712 Information Exposure vulnerability in Apache Airflow
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be masked in the UI. Users are strongly advised to upgrade to version 2.7.1 or later which has removed the vulnerability.
network
low complexity
apache CWE-200
6.5
2023-08-23 CVE-2023-37379 Unspecified vulnerability in Apache Airflow
Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection edit privileges.
network
low complexity
apache
8.1
2023-08-23 CVE-2023-39441 Improper Certificate Validation vulnerability in Apache Airflow
Apache Airflow SMTP Provider before 1.3.0, Apache Airflow IMAP Provider before 3.3.0, and Apache Airflow before 2.7.0 are affected by the Validation of OpenSSL Certificate vulnerability. The default SSL context with SSL library did not check a server's X.509 certificate.  Instead, the code accepted any certificate, which could result in the disclosure of mail server credentials or mail contents when the client connects to an attacker in a MITM position. Users are strongly advised to upgrade to Apache Airflow version 2.7.0 or newer, Apache Airflow IMAP Provider version 3.3.0 or newer, and Apache Airflow SMTP Provider version 1.3.0 or newer to mitigate the risk associated with this vulnerability
network
high complexity
apache CWE-295
5.9
2023-08-23 CVE-2023-40273 Session Fixation vulnerability in Apache Airflow
The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the password of the user has been reset by the admin - up until the expiry of the session of the user.
network
low complexity
apache CWE-384
8.0