Skip to content
Apache AirflowGHSA-5938-79hg-xh3q

Apache Airflow Improper Access Control vulnerability

Medium6.5CVE-2023-50783 · Published Dec 21, 2023 · updated Nov 21, 2024

Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable. This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification. Users are recommended to upgrade to 2.8.0, which fixes this issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.8.02.8.0
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow: Bypass permission verification to read code of other dags
High6.5Jan 24, 2024
Apache Airflow: cleartext storage
Medium6.5Jan 24, 2024
Apache Airflow: pickle deserialization vulnerability in XComs
High7.5Jan 24, 2024
Apache Airflow Cross-Site Request Forgery vulnerability
Medium6.5Dec 21, 2023
Apache Airflow vulnerable to Exposure of Resource to Wrong Sphere
Medium4.3Dec 21, 2023
Apache Airflow has a stored cross-site scripting vulnerability
Medium5.4Dec 21, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.