Skip to content
Apache AirflowGHSA-6xwf-xvf3-v459

Apache Airflow: Incorrect Default Permissions in audit logs for Ops and Viewers users

Medium4.7CVE-2024-26280 · Published Mar 1, 2024 · updated Nov 1, 2024

Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated Ops and Viewers users to view all information on audit logs, including dag names and usernames they were not permitted to view. With 2.8.2 and newer, Ops and Viewer users do not have audit log permission by default, they need to be explicitly granted permissions to see the logs. Only admin users have audit log permission by default. Users of Apache Airflow are recommended to upgrade to version 2.8.2 or newer to mitigate the risk associated with this vulnerability

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.8.22.8.2
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow Improper Preservation of Permissions vulnerability
Medium5.3Mar 26, 2024
Apache Airflow: Ignored Airflow Permission
MediumMar 14, 2024
Apache Airflow: DAG Code and Import Error Permissions Ignored
MediumFeb 29, 2024
Apache Airflow: pickle deserialization vulnerability in XComs
High7.5Jan 24, 2024
Apache Airflow: cleartext storage
Medium6.5Jan 24, 2024
Apache Airflow: Bypass permission verification to read code of other dags
High6.5Jan 24, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.