Apache AirflowGHSA-h88f-r7cw-8fv3
Missing Authentication for Critical Function in Apache Airflow
Critical9.8CVE-2021-38540 · Published May 24, 2022 · updated Sep 11, 2024
The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution. This issue affects Apache Airflow >=2.0.0, <2.1.3.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | >= 2.0.0, < 2.1.3 | 2.1.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-306
- Also known as
- BIT-airflow-2021-38540, CVE-2021-38540, PYSEC-2021-326
- nvd.nist.gov/vuln/detail/CVE-2021-38540
- github.com/apache/airflow/commit/bcec1df703cd4a01520a90c3f801cca6f97d9bfd
- github.com/advisories/GHSA-h88f-r7cw-8fv3
- github.com/apache/airflow
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2021-326.yaml
- lists.apache.org/thread.html/rac2ed9118f64733e47b4f1e82ddc8c8020774698f13328ca742b03a2@%3Cannounce.apache.org%3E
- lists.apache.org/thread.html/rb34c3dd1a815456355217eef34060789f771b6f77c3a3dec77de2064%40%3Cusers.airflow.apache.org%3E
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 32022 | Apache Airflow exposes arbitrary file content | Medium4.7 | 2.3.4 |
| Sep 32022 | Apache Airflow Session Fixation vulnerability | Critical9.8 | 2.3.4rc1 |
| May 142022 | Apache Airflow Reflected Cross-site Scripting vulnerability in 404 Endpoint | Medium6.1 | 1.9.0 |
| Feb 262022 | Apache Airflow Cross-site Scripting Vulnerability | Medium6.1 | 2.2.4rc1 |
| Feb 262022 | OS Command injection in Apache Airflow | High8.8 | 2.2.4 |
| Jan 282022 | Improper Privilege Management in apache-airflow | Medium6.5 | 2.2.0 |