[ https://issues.apache.org/jira/browse/AIRFLOW-1765?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Bolke de Bruin resolved AIRFLOW-1765. ------------------------------------- Resolution: Fixed Issue resolved by pull request #2737 [https://github.com/apache/incubator-airflow/pull/2737] > Default API auth backed should deny all. > ---------------------------------------- > > Key: AIRFLOW-1765 > URL: https://issues.apache.org/jira/browse/AIRFLOW-1765 > Project: Apache Airflow > Issue Type: Improvement > Components: api, authentication > Affects Versions: 1.8.2 > Reporter: Ash Berlin-Taylor > Priority: Major > Labels: security > Fix For: 1.9.0 > > > It has been discovered that the experimental API in the default configuration > is not protected behind any authentication. > This means that out of the box the Airflow webserver's /api/experimental/ can > be requested by anyone, meaning pools can be updated/deleted and task > instance variables can be read. -- This message was sent by Atlassian JIRA (v6.4.14#64029)