Improper Access Control Affecting apache-airflow package, versions [,2.8.0b1)
Threat Intelligence
EPSS
0.1% (44th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-APACHEAIRFLOW-6137747
- published 21 Dec 2023
- disclosed 21 Dec 2023
- credit balis0ng
Introduced: 21 Dec 2023
CVE-2023-48291 Open this link in a new tabHow to fix?
Upgrade apache-airflow
to version 2.8.0b1 or higher.
Overview
apache-airflow is a platform to programmatically author, schedule, and monitor workflows.
Affected versions of this package are vulnerable to Improper Access Control allowing an authenticated user with limited access to some DAG
s, to craft a request that could give the user write access to various DAG
resources that the user had no access to.
NOTE: This was thought to be fixed in version 2.7.2, with the publication of CVE-2023-42792, but it was missed.
CVSS Scores
version 3.1