Skip to content
Apache AirflowGHSA-3h4m-m55v-gx4m

Apache Airflow Improper Input Validation vulnerability

High6.5CVE-2023-36543 · Published Jul 12, 2023 · updated Nov 24, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.6.32.6.3
Details and references

Apache Airflow, versions before 2.6.3, has a vulnerability where an authenticated user can use crafted input to make the current request hang. It is recommended to upgrade to a version that is not affected

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-1333, CWE-20
Also known as
BIT-airflow-2023-36543, CVE-2023-36543, PYSEC-2023-106

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Jul 122023Apache Airflow information disclosure vulnerability
CVE-2022-46651High6.5fixed in 2.6.3
Jul 122023Apache Airflow Incorrect Authorization vulnerability
CVE-2023-35908High6.5fixed in 2.6.3
Jul 122023Apache Airflow Improper Input Validation vulnerability
CVE-2023-22888High6.5fixed in 2.6.3
Jul 122023Apache Airflow Path Traversal vulnerability
CVE-2023-22887High6.5fixed in 2.6.3
Jun 192023Apache Airflow vulnerable to exposure of sensitive information
CVE-2023-35005High6.5fixed in 2.6.2rc1
Aug 52023Apache Airflow Execution with Unnecessary Privileges
CVE-2023-39508High8.8fixed in 2.6.0b1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.