Apache AirflowGHSA-ffw3-6mp6-jmvj
Improper Access Control in Apache Airflow
High6.5CVE-2021-26559 · Published Apr 7, 2021 · updated Nov 18, 2024
Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow.cfg`. This allowed a privilege escalation attack. This issue affects Apache Airflow 2.0.0.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | >= 2.0.0, < 2.0.1rc1 | 2.0.1rc1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-269, CWE-284
- Also known as
- BIT-airflow-2021-26559, CVE-2021-26559, PYSEC-2021-2
- nvd.nist.gov/vuln/detail/CVE-2021-26559
- github.com/apache/airflow/commit/3909232fafd09ac72b49010ecdfd6ea48f06d5cf
- github.com/apache/airflow/commit/5e35926c7eda0dfa11a9623e4bf5f60c2bd6b3f6
- github.com/advisories/GHSA-ffw3-6mp6-jmvj
- github.com/apache/airflow
- github.com/apache/airflow/blob/486b76438c0679682cf98cb88ed39c4b161cbcc8/CHANGELOG.txt
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2021-2.yaml
- lists.apache.org/thread.html/r3b3787700279ec361308cbefb7c2cce2acb26891a12ce864e4a13c8d%40%3Cusers.airflow.apache.org%3E
- lists.apache.org/thread.html/rd142565996d7ee847b9c14b8a9921dcf80bc6bc160e3d9dca6dfc2f8@%3Cannounce.apache.org%3E
- www.openwall.com/lists/oss-security/2021/02/17/1
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 182021 | Cross-site Scripting in Apache Airflow | Medium6.1 | 1.10.15+1 more |
| Jun 182021 | Improper Authentication in Apache Airflow | Medium5.3 | 2.0.1rc1 |
| Jun 182021 | Apache Airflow Cross-site Scripting | Medium6.1 | 1.10.12 |
| Apr 302021 | Authentication bypass in Apache Airflow | Critical9.8 | 1.10.11 |
| Apr 202021 | Incorrect Session Validation in Apache Airflow | High7.7 | 1.10.14 |
| Apr 202021 | Apache Airflow cross-site scripting due to incomplete fix for CVE-2020-13944 | Medium6.1 | 1.10.15rc1+1 more |