QID 995612

Date Published: 2023-10-18

QID 995612: Python (Pip) Security Update for apache-airflow (GHSA-j3w8-2p2h-mrr9)

Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could give the user write access to various DAG resources for DAGs that the user had no access to, thus, enabling the user to clear DAGs they shouldn't.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-j3w8-2p2h-mrr9 for updates and patch information.
    Vendor References

    CVEs related to QID 995612

    Software Advisories
    Advisory ID Software Component Link
    GHSA-j3w8-2p2h-mrr9 apache-airflow URL Logo github.com/advisories/GHSA-j3w8-2p2h-mrr9