{"api_version":"1","generated_at":"2026-07-23T11:53:41+00:00","cve":"CVE-2023-40611","urls":{"html":"https://cve.report/CVE-2023-40611","api":"https://cve.report/api/cve/CVE-2023-40611.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-40611","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-40611"},"summary":{"title":"CVE-2023-40611","description":"Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.\n\nUsers should upgrade to version 2.7.1 or later which has removed the vulnerability.","state":"PUBLIC","assigner":"security@apache.org","published_at":"2023-09-12 12:15:00","updated_at":"2023-11-12 15:15:00"},"problem_types":["CWE-863"],"metrics":[],"references":[{"url":"https://github.com/apache/airflow/pull/33413","name":"https://github.com/apache/airflow/pull/33413","refsource":"MISC","tags":[],"title":"Add read only validation to read only fields by ahidalgob · Pull Request #33413 · apache/airflow · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2023/11/12/1","name":"http://www.openwall.com/lists/oss-security/2023/11/12/1","refsource":"","tags":[],"title":"oss-security - CVE-2023-47037: Apache Airflow missing fix for CVE-2023-40611 in\n 2.7.1 (DAG run broken access)","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.apache.org/thread/8y9xk1s3j4qr36yzqn8ogbn9fl7pxrn0","name":"https://lists.apache.org/thread/8y9xk1s3j4qr36yzqn8ogbn9fl7pxrn0","refsource":"MISC","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-40611","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40611","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"40611","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"airflow","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-40611","ASSIGNER":"security@apache.org","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.\n\nUsers should upgrade to version 2.7.1 or later which has removed the vulnerability.\n"}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-863 Incorrect Authorization","cweId":"CWE-863"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Apache Software Foundation","product":{"product_data":[{"product_name":"Apache Airflow","version":{"version_data":[{"version_affected":"<","version_name":"0","version_value":"2.7.1"}]}}]}}]}},"references":{"reference_data":[{"url":"https://github.com/apache/airflow/pull/33413","refsource":"MISC","name":"https://github.com/apache/airflow/pull/33413"},{"url":"https://lists.apache.org/thread/8y9xk1s3j4qr36yzqn8ogbn9fl7pxrn0","refsource":"MISC","name":"https://lists.apache.org/thread/8y9xk1s3j4qr36yzqn8ogbn9fl7pxrn0"}]},"generator":{"engine":"Vulnogram 0.1.0-dev"},"source":{"discovery":"UNKNOWN"},"credits":[{"lang":"en","value":"happyhacking"}]},"nvd":{"publishedDate":"2023-09-12 12:15:00","lastModifiedDate":"2023-11-12 15:15:00","problem_types":["CWE-863"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*","versionEndExcluding":"2.7.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}