Skip to content
Apache AirflowGHSA-vm5m-qmrx-fw8w

Apache Airflow: Bypass permission verification to read code of other dags

High6.5CVE-2023-50944 · Published Jan 24, 2024 · updated Feb 13, 2025

Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don't have access. This vulnerability is considered low since it requires an authenticated user to exploit it. Users are recommended to upgrade to version 2.8.1, which fixes this issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.8.1rc12.8.1rc1
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow: pickle deserialization vulnerability in XComs
High7.5Jan 24, 2024
Apache Airflow: cleartext storage
Medium6.5Jan 24, 2024
Apache Airflow Improper Access Control vulnerability
Medium6.5Dec 21, 2023
Apache Airflow Cross-Site Request Forgery vulnerability
Medium6.5Dec 21, 2023
Apache Airflow vulnerable to Exposure of Resource to Wrong Sphere
Medium4.3Dec 21, 2023
Apache Airflow has a stored cross-site scripting vulnerability
Medium5.4Dec 21, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.