Skip to content
Apache AirflowGHSA-269x-pg5c-5xgm

Apache Airflow Execution with Unnecessary Privileges

High8.8CVE-2023-39508 · Published Aug 5, 2023 · updated Feb 13, 2025

Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Airflow.The "Run Task" feature enables authenticated user to bypass some of the restrictions put in place. It allows to execute code in the webserver context as well as allows to bypas limitation of access the user has to certain DAGs. The "Run Task" feature is considered dangerous and it has been removed entirely in Airflow 2.6.0. This issue affects Apache Airflow: before 2.6.0.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.6.0b12.6.0b1
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow denial of service vulnerability
High8.1Aug 23, 2023
Apache Airflow Session Fixation vulnerability
High8.0Aug 23, 2023
Apache Airflow missing Certificate Validation
Medium5.9Aug 23, 2023
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider
High7.5Aug 11, 2023
Apache Airflow Incorrect Authorization vulnerability
High6.5Jul 12, 2023
Apache Airflow Improper Input Validation vulnerability
High6.5Jul 12, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.