Skip to content
Apache AirflowGHSA-6v6w-h8m6-7mv2

Apache Airflow: DAG Code and Import Error Permissions Ignored

MediumCVE-2024-27906 · Published Feb 29, 2024 · updated May 6, 2025

Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not have permission to view through the API and the UI. Users of Apache Airflow are recommended to upgrade to version 2.8.2 or newer to mitigate the risk associated with this vulnerability

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.8.22.8.2
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow Improper Preservation of Permissions vulnerability
Medium5.3Mar 26, 2024
Apache Airflow: Ignored Airflow Permission
MediumMar 14, 2024
Apache Airflow: Incorrect Default Permissions in audit logs for Ops and Viewers users
Medium4.7Mar 1, 2024
Apache Airflow: pickle deserialization vulnerability in XComs
High7.5Jan 24, 2024
Apache Airflow: cleartext storage
Medium6.5Jan 24, 2024
Apache Airflow: Bypass permission verification to read code of other dags
High6.5Jan 24, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.