Skip to content
Apache AirflowGHSA-6m9r-7wrx-xmr6

Apache Airflow Cross-Site Request Forgery vulnerability

Medium6.5CVE-2023-49920 · Published Dec 21, 2023 · updated Nov 21, 2024

Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. As a result, it was possible for a malicious website opened in the same browser - by the user who also had Airflow UI opened - to trigger the execution of DAGs without the user's consent. Users are advised to upgrade to version 2.8.0 or later which is not affected

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
>= 2.7.0, < 2.8.02.8.0
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow: Bypass permission verification to read code of other dags
High6.5Jan 24, 2024
Apache Airflow: cleartext storage
Medium6.5Jan 24, 2024
Apache Airflow: pickle deserialization vulnerability in XComs
High7.5Jan 24, 2024
Apache Airflow Improper Access Control vulnerability
Medium6.5Dec 21, 2023
Apache Airflow vulnerable to Exposure of Resource to Wrong Sphere
Medium4.3Dec 21, 2023
Apache Airflow has a stored cross-site scripting vulnerability
Medium5.4Dec 21, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.