Severity: moderate

Affected versions:

- Apache Airflow before 2.8.2

Description:

Apache Airflow, versions before 2.8.2, has a vulnerability that allows 
authenticated users to view DAG code and import errors of DAGs they do not have 
permission to view through the API and the UI.

Users of Apache Airflow are recommended to upgrade to version 2.8.2 or newer to 
mitigate the risk associated with this vulnerability

Credit:

Alex Liotta (finder)
Sreenivasulu Suuda (finder)
vincbeck (Vincent) (remediation developer)
Jed Cunningham (remediation developer)

References:

https://github.com/apache/airflow/pull/37290
https://github.com/apache/airflow/pull/37468
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-27906


---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscr...@airflow.apache.org
For additional commands, e-mail: users-h...@airflow.apache.org

Reply via email to