oss-sec mailing list archives

CVE-2024-28746: Apache Airflow: Ignored Airflow Permissions


From: Ephraim Anierobi <ephraimanierobi () apache org>
Date: Wed, 13 Mar 2024 17:50:30 +0000

Severity: moderate

Affected versions:

- Apache Airflow 2.8.0 before 2.8.3

Description:

Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited 
permissions to access resources such as variables, connections, etc from the UI which they do not have permission to 
access. 

Users of Apache Airflow are recommended to upgrade to version 2.8.3 or newer to mitigate the risk associated with this 
vulnerability

Credit:

Alex Liotta (finder)
Vincent(Vincbeck) (remediation developer)

References:

https://github.com/apache/airflow/pull/37881
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-28746


Current thread: