Skip to content
Apache AirflowGHSA-4jh2-3c85-q67h

Improper Privilege Management in apache-airflow

Medium6.5CVE-2021-45230 · Published Jan 28, 2022 · updated Sep 3, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.2.02.2.0
Details and references

In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-269
Also known as
BIT-airflow-2021-45230, CVE-2021-45230, PYSEC-2022-11

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Feb 262022OS Command injection in Apache Airflow
CVE-2022-24288High8.8fixed in 2.2.4
Feb 262022Apache Airflow Cross-site Scripting Vulnerability
CVE-2021-45229Medium6.1fixed in 2.2.4rc1
May 142022Apache Airflow Reflected Cross-site Scripting vulnerability in 404 Endpoint
CVE-2017-12614Medium6.1fixed in 1.9.0
May 242022Missing Authentication for Critical Function in Apache Airflow
CVE-2021-38540Critical9.8fixed in 2.1.3
Aug 302021Missing Authorization in Apache Airflow
CVE-2021-35936Medium5.3fixed in 2.1.2
Sep 32022Apache Airflow Session Fixation vulnerability
CVE-2022-38054Critical9.8fixed in 2.3.4rc1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.