QID 995612
Date Published: 2023-10-18
QID 995612: Python (Pip) Security Update for apache-airflow (GHSA-j3w8-2p2h-mrr9)
Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could give the user write access to various DAG resources for DAGs that the user had no access to, thus, enabling the user to clear DAGs they shouldn't.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-j3w8-2p2h-mrr9 for updates and patch information.
Vendor References
- GHSA-j3w8-2p2h-mrr9 -
github.com/advisories/GHSA-j3w8-2p2h-mrr9
CVEs related to QID 995612
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-j3w8-2p2h-mrr9 | apache-airflow |
|