Skip to content
Apache AirflowGHSA-x2mh-8fmc-rqgh

Apache Airflow denial of service vulnerability

High8.1CVE-2023-37379 · Published Aug 23, 2023 · updated Feb 13, 2025

Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection edit privileges. This vulnerability allows the user to access connection information and exploit the test connection feature by sending many requests, leading to a denial of service (DoS) condition on the server. Furthermore, malicious actors can leverage this vulnerability to establish harmful connections with the server. Users of Apache Airflow are strongly advised to upgrade to version 2.7.0 or newer to mitigate the risk associated with this vulnerability. Additionally, administrators are encouraged to review and adjust user permissions to restrict access to sensitive functionalities, reducing the attack surface.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.7.0b12.7.0b1
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow information exposure vulnerability
High6.5Sep 12, 2023
Apache Airflow Incorrect Authorization vulnerability
Medium4.3Sep 12, 2023
Apache Airflow missing Certificate Validation
Medium5.9Aug 23, 2023
Apache Airflow Session Fixation vulnerability
High8.0Aug 23, 2023
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider
High7.5Aug 11, 2023
Apache Airflow Execution with Unnecessary Privileges
High8.8Aug 5, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.