Skip to content
Apache AirflowGHSA-h574-6646-vfxx

Apache Airflow: Ignored Airflow Permission

MediumCVE-2024-28746 · Published Mar 14, 2024 · updated Dec 6, 2024

Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access.  Users of Apache Airflow are recommended to upgrade to version 2.8.3 or newer to mitigate the risk associated with this vulnerability

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
>= 2.8.0, < 2.8.3rc12.8.3rc1
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
Medium4.3Apr 18, 2024
Apache Airflow Improper Preservation of Permissions vulnerability
Medium5.3Mar 26, 2024
Apache Airflow: Incorrect Default Permissions in audit logs for Ops and Viewers users
Medium4.7Mar 1, 2024
Apache Airflow: DAG Code and Import Error Permissions Ignored
MediumFeb 29, 2024
Apache Airflow: pickle deserialization vulnerability in XComs
High7.5Jan 24, 2024
Apache Airflow: cleartext storage
Medium6.5Jan 24, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.