Hi, Airflow community, Please find below the information about a vulnerability that has been addressed in Apache Airflow v2.2.0+:
*Description*: This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for. This is a very low severity CVE and admins can mitigate this issue by removing the global "can_create" permissions on DagRun for Airflow versions >=2.0.0,<2.2.0 and 1.10.x versions that have set `rbac=True` in config. *Credit*: Apache Airflow PMC would like to thank Franco Cano Erazo for reporting this issue. Thanks. Kaxil @ Airflow PMC
