Skip to content
Apache AirflowGHSA-q8h9-pqcx-59hw

Apache Airflow exposes arbitrary file content

Medium4.7CVE-2022-38170 · Published Sep 3, 2022 · updated Sep 11, 2024

In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local users to expose arbitrary file contents via the webserver.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.3.42.3.4
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow Cross-site Scripting vulnerability
Medium6.1Nov 2, 2022
Apache Airflow Open Redirect vulnerability
Medium6.1Nov 2, 2022
Apache Airflow may allow authenticated users who have been deactivated to continue using the UI or API
High8.1Oct 7, 2022
Apache Airflow vulnerable to Use of Externally-Controlled Format String
High7.5Sep 22, 2022
Apache Airflow contains open redirect
Medium6.1Sep 22, 2022
Apache Airflow Session Fixation vulnerability
Critical9.8Sep 3, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.