eladkal commented on issue #70676:
URL: https://github.com/apache/airflow/issues/70676#issuecomment-5127305724

   > A remote authenticated attacker (Airflow user with trigger permission) can 
block Airflow worker slots indefinitely by triggering DAG runs with crafted 
application_args
   
   This maybe(?) a possible bug but this is not a security risk. This report is 
based on autenticated user with full permissions by design acting as an 
attacker. This is not valid. This is not a case of malicious actor getting 
permissions that he shouldn't have.
   
   In any case int he future please do not file security voluntarily publicly. 
Please read the project security policy and how security reports should be 
filed.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to