Skip to content
Apache AirflowGHSA-h88f-r7cw-8fv3

Missing Authentication for Critical Function in Apache Airflow

Critical9.8CVE-2021-38540 · Published May 24, 2022 · updated Sep 11, 2024

The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution. This issue affects Apache Airflow >=2.0.0, <2.1.3.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
>= 2.0.0, < 2.1.32.1.3
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow exposes arbitrary file content
Medium4.7Sep 3, 2022
Apache Airflow Session Fixation vulnerability
Critical9.8Sep 3, 2022
Apache Airflow Reflected Cross-site Scripting vulnerability in 404 Endpoint
Medium6.1May 14, 2022
Apache Airflow Cross-site Scripting Vulnerability
Medium6.1Feb 26, 2022
OS Command injection in Apache Airflow
High8.8Feb 26, 2022
Improper Privilege Management in apache-airflow
Medium6.5Jan 28, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.