Apache AirflowGHSA-h574-6646-vfxx
Apache Airflow: Ignored Airflow Permission
MediumCVE-2024-28746 · Published Mar 14, 2024 · updated Dec 6, 2024
Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access. Users of Apache Airflow are recommended to upgrade to version 2.8.3 or newer to mitigate the risk associated with this vulnerability
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | >= 2.8.0, < 2.8.3rc1 | 2.8.3rc1 |
Details and references
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-281
- Also known as
- BIT-airflow-2024-28746, CVE-2024-28746, PYSEC-2024-46
- nvd.nist.gov/vuln/detail/CVE-2024-28746
- github.com/apache/airflow/pull/37881
- github.com/apache/airflow/commit/89e7f3e7bdf2126bbbcd959dc10d65ef92773cca
- github.com/apache/airflow
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2024-46.yaml
- lists.apache.org/thread/b4pffc7w7do6qgk4jjbyxvdz5odrvny7
- www.openwall.com/lists/oss-security/2024/03/13/5
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 182024 | Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used | Medium4.3 | 2.9.0 |
| Mar 262024 | Apache Airflow Improper Preservation of Permissions vulnerability | Medium5.3 | 2.8.4 |
| Mar 12024 | Apache Airflow: Incorrect Default Permissions in audit logs for Ops and Viewers users | Medium4.7 | 2.8.2 |
| Feb 292024 | Apache Airflow: DAG Code and Import Error Permissions Ignored | Medium | 2.8.2 |
| Jan 242024 | Apache Airflow: pickle deserialization vulnerability in XComs | High7.5 | 2.8.1rc1 |
| Jan 242024 | Apache Airflow: cleartext storage | Medium6.5 | 2.6.1 |