Apache AirflowGHSA-hm9r-7f84-25c9
Apache Airflow allows authenticated and DAG-view authorized users to modify some DAG run detail values when submitting notes
Medium4.3CVE-2023-47037 · Published Nov 12, 2023 · updated Feb 13, 2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | < 2.7.3 | 2.7.3 |
Details and references
Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc. Users should upgrade to version 2.7.3 or later which has removed the vulnerability.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-285, CWE-863
- Also known as
- BIT-airflow-2023-47037, CVE-2023-47037, PYSEC-2023-232
- nvd.nist.gov/vuln/detail/CVE-2023-47037
- github.com/apache/airflow/pull/33413
- github.com/apache/airflow/commit/2a0106e4edf67c5905ebfcb82a6008662ae0f7ad
- github.com/apache/airflow/commit/b7a46c970d638028a4a7643ad000dcee951fb9ef
- github.com/apache/airflow
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2023-232.yaml
- lists.apache.org/thread/04y4vrw1t2xl030gswtctc4nt1w90cb0
- www.openwall.com/lists/oss-security/2023/11/12/1
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Nov 122023 | Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor CVE-2023-42781High6.5fixed in 2.7.3 | High6.5 | 2.7.3 |
| Oct 282023 | Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability CVE-2023-46215High7.5fixed in 2.7.0 | High7.5 | 2.7.0 |
| Oct 232023 | Apache Airflow vulnerable to Exposure of Sensitive Information CVE-2023-46288Medium4.3fixed in 2.7.2 | Medium4.3 | 2.7.2 |
| Oct 142023 | Apache Airflow vulnerable to sensitive information exposure CVE-2023-42663Medium6.5fixed in 2.7.2 | Medium6.5 | 2.7.2 |
| Oct 142023 | Apache Airflow vulnerable to sensitive information exposure when users list warnings for all DAGs CVE-2023-42780Medium6.5fixed in 2.7.2 | Medium6.5 | 2.7.2 |
| Oct 142023 | Apache Airflow vulnerable to sensitive information exposure when expose-config is set to non-sensitive-only CVE-2023-45348Medium4.3fixed in 2.7.2 | Medium4.3 | 2.7.2 |