QID 994799
Date Published: 2023-08-10
QID 994799: Python (Pip) Security Update for apache-airflow (GHSA-269x-pg5c-5xgm)
Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Airflow.The "Run Task" feature enables authenticated user to bypass some of the restrictions put in place. It allows to execute code in the webserver context as well as allows to bypas limitation of access the user has to certain DAGs. The "Run Task" feature is considered dangerous and it has been removed entirely in Airflow 2.6.0.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-269x-pg5c-5xgm for updates and patch information.
Vendor References
- GHSA-269x-pg5c-5xgm -
github.com/advisories/GHSA-269x-pg5c-5xgm
CVEs related to QID 994799
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-269x-pg5c-5xgm | apache-airflow |
|