Apache AirflowGHSA-4jh2-3c85-q67h
Improper Privilege Management in apache-airflow
Medium6.5CVE-2021-45230 · Published Jan 28, 2022 · updated Sep 3, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | < 2.2.0 | 2.2.0 |
Details and references
In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-269
- Also known as
- BIT-airflow-2021-45230, CVE-2021-45230, PYSEC-2022-11
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 262022 | OS Command injection in Apache Airflow CVE-2022-24288High8.8fixed in 2.2.4 | High8.8 | 2.2.4 |
| Feb 262022 | Apache Airflow Cross-site Scripting Vulnerability CVE-2021-45229Medium6.1fixed in 2.2.4rc1 | Medium6.1 | 2.2.4rc1 |
| May 142022 | Apache Airflow Reflected Cross-site Scripting vulnerability in 404 Endpoint CVE-2017-12614Medium6.1fixed in 1.9.0 | Medium6.1 | 1.9.0 |
| May 242022 | Missing Authentication for Critical Function in Apache Airflow CVE-2021-38540Critical9.8fixed in 2.1.3 | Critical9.8 | 2.1.3 |
| Aug 302021 | Missing Authorization in Apache Airflow CVE-2021-35936Medium5.3fixed in 2.1.2 | Medium5.3 | 2.1.2 |
| Sep 32022 | Apache Airflow Session Fixation vulnerability CVE-2022-38054Critical9.8fixed in 2.3.4rc1 | Critical9.8 | 2.3.4rc1 |