Skip to content
Apache AirflowGHSA-m6h2-jx9v-58w6

Missing Authorization in Apache Airflow

Medium5.3CVE-2021-35936 · Published Aug 30, 2021 · updated Sep 11, 2024

If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor) runs a Flask logging server and is listening on a specific port and also binds on 0.0.0.0 by default. This logging server had no authentication and allows reading log files of DAG jobs. This issue affects Apache Airflow < 2.1.2.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.1.22.1.2
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Cross-site Scripting in Apache Airflow
Medium6.1Jun 18, 2021
Improper Authentication in Apache Airflow
Medium5.3Jun 18, 2021
Apache Airflow Cross-site Scripting
Medium6.1Jun 18, 2021
Authentication bypass in Apache Airflow
Critical9.8Apr 30, 2021
Incorrect Session Validation in Apache Airflow
High7.7Apr 20, 2021
Apache Airflow cross-site scripting due to incomplete fix for CVE-2020-13944
Medium6.1Apr 20, 2021

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.