Apache AirflowGHSA-5938-79hg-xh3q
Apache Airflow Improper Access Control vulnerability
Medium6.5CVE-2023-50783 · Published Dec 21, 2023 · updated Nov 21, 2024
Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable. This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification. Users are recommended to upgrade to 2.8.0, which fixes this issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | < 2.8.0 | 2.8.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-284
- Also known as
- BIT-airflow-2023-50783, CVE-2023-50783, PYSEC-2023-267
- nvd.nist.gov/vuln/detail/CVE-2023-50783
- github.com/apache/airflow/pull/33932
- github.com/apache/airflow/commit/0e1c106d7cd0703125528a691088e42e17c99929
- github.com/apache/airflow
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2023-267.yaml
- lists.apache.org/thread/rs7cr3yp726mb89s1m844hy9pq7frgcn
- www.openwall.com/lists/oss-security/2023/12/21/4
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 242024 | Apache Airflow: Bypass permission verification to read code of other dags | High6.5 | 2.8.1rc1 |
| Jan 242024 | Apache Airflow: cleartext storage | Medium6.5 | 2.6.1 |
| Jan 242024 | Apache Airflow: pickle deserialization vulnerability in XComs | High7.5 | 2.8.1rc1 |
| Dec 212023 | Apache Airflow Cross-Site Request Forgery vulnerability | Medium6.5 | 2.8.0 |
| Dec 212023 | Apache Airflow vulnerable to Exposure of Resource to Wrong Sphere | Medium4.3 | 2.8.0 |
| Dec 212023 | Apache Airflow has a stored cross-site scripting vulnerability | Medium5.4 | 2.8.0b1 |