Skip to content
Apache AirflowGHSA-8f57-wcmg-4jmh

Apache Airflow vulnerable to Exposure of Resource to Wrong Sphere

Medium4.3CVE-2023-48291 · Published Dec 21, 2023 · updated Nov 21, 2024

Apache Airflow, in versions prior to 2.8.0, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could give the user write access to various DAG resources for DAGs that the user had no access to, thus, enabling the user to clear DAGs they shouldn't. This is a missing fix for CVE-2023-42792 in Apache Airflow 2.7.2  Users of Apache Airflow are strongly advised to upgrade to version 2.8.0 or newer to mitigate the risk associated with this vulnerability.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.8.02.8.0
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow: Bypass permission verification to read code of other dags
High6.5Jan 24, 2024
Apache Airflow: cleartext storage
Medium6.5Jan 24, 2024
Apache Airflow: pickle deserialization vulnerability in XComs
High7.5Jan 24, 2024
Apache Airflow Improper Access Control vulnerability
Medium6.5Dec 21, 2023
Apache Airflow Cross-Site Request Forgery vulnerability
Medium6.5Dec 21, 2023
Apache Airflow has a stored cross-site scripting vulnerability
Medium5.4Dec 21, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.