Skip to content
Apache AirflowGHSA-wpg8-mf6h-gm92

Apache Airflow Incorrect Authorization vulnerability

Medium4.3CVE-2023-40611 · Published Sep 12, 2023 · updated Feb 13, 2025

Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc. Users should upgrade to version 2.7.1 or later which has removed the vulnerability.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.7.12.7.1
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow vulnerable to privilege escalation
Medium6.5Oct 14, 2023
Apache Airflow information exposure vulnerability
High6.5Sep 12, 2023
Apache Airflow missing Certificate Validation
Medium5.9Aug 23, 2023
Apache Airflow Session Fixation vulnerability
High8.0Aug 23, 2023
Apache Airflow denial of service vulnerability
High8.1Aug 23, 2023
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider
High7.5Aug 11, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.