Skip to content
Apache AirflowGHSA-5946-8p38-vffp

Apache Airflow Improper Input Validation vulnerability

High6.5CVE-2023-22888 · Published Jul 12, 2023 · updated Nov 24, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.6.32.6.3
Details and references

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to cause a service disruption by manipulating the run_id parameter. This vulnerability is considered low since it requires an authenticated user to exploit it. It is recommended to upgrade to a version that is not affected

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20
Also known as
BIT-airflow-2023-22888, CVE-2023-22888, PYSEC-2023-105

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Jul 122023Apache Airflow information disclosure vulnerability
CVE-2022-46651High6.5fixed in 2.6.3
Jul 122023Apache Airflow Incorrect Authorization vulnerability
CVE-2023-35908High6.5fixed in 2.6.3
Jul 122023Apache Airflow Improper Input Validation vulnerability
CVE-2023-36543High6.5fixed in 2.6.3
Jul 122023Apache Airflow Path Traversal vulnerability
CVE-2023-22887High6.5fixed in 2.6.3
Jun 192023Apache Airflow vulnerable to exposure of sensitive information
CVE-2023-35005High6.5fixed in 2.6.2rc1
Aug 52023Apache Airflow Execution with Unnecessary Privileges
CVE-2023-39508High8.8fixed in 2.6.0b1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.