Skip to content
Apache AirflowGHSA-ggwr-4vr8-g7wv

Apache Airflow Path Traversal vulnerability

High6.5CVE-2023-22887 · Published Jul 12, 2023 · updated Nov 24, 2024

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to perform unauthorized file access outside the intended directory structure by manipulating the run_id parameter. This vulnerability is considered low since it requires an authenticated user to exploit it. It is recommended to upgrade to a version that is not affected

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.6.32.6.3
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow Execution with Unnecessary Privileges
High8.8Aug 5, 2023
Apache Airflow Incorrect Authorization vulnerability
High6.5Jul 12, 2023
Apache Airflow Improper Input Validation vulnerability
High6.5Jul 12, 2023
Apache Airflow Improper Input Validation vulnerability
High6.5Jul 12, 2023
Apache Airflow information disclosure vulnerability
High6.5Jul 12, 2023
Apache Airflow vulnerable to exposure of sensitive information
High6.5Jun 19, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.