Skip to content
Apache AirflowGHSA-2h84-3crq-vgfj

Apache Airflow Incorrect Authorization vulnerability

High6.5CVE-2023-35908 · Published Jul 12, 2023 · updated Feb 13, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.6.32.6.3
Details and references

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommended to upgrade to a version that is not affected

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-863
Also known as
BIT-airflow-2023-35908, CVE-2023-35908, PYSEC-2023-119

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Jul 122023Apache Airflow information disclosure vulnerability
CVE-2022-46651High6.5fixed in 2.6.3
Jul 122023Apache Airflow Improper Input Validation vulnerability
CVE-2023-36543High6.5fixed in 2.6.3
Jul 122023Apache Airflow Improper Input Validation vulnerability
CVE-2023-22888High6.5fixed in 2.6.3
Jul 122023Apache Airflow Path Traversal vulnerability
CVE-2023-22887High6.5fixed in 2.6.3
Jun 192023Apache Airflow vulnerable to exposure of sensitive information
CVE-2023-35005High6.5fixed in 2.6.2rc1
Aug 52023Apache Airflow Execution with Unnecessary Privileges
CVE-2023-39508High8.8fixed in 2.6.0b1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.