Exposure of Resource to Wrong Sphere Affecting apache-airflow package, versions [,2.8.2)
Threat Intelligence
EPSS
0.05% (17th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-APACHEAIRFLOW-6346759
- published 1 Mar 2024
- disclosed 29 Feb 2024
- credit Sreenivasulu Suuda, Alex Liotta
Introduced: 29 Feb 2024
CVE-2024-27906 Open this link in a new tabHow to fix?
Upgrade apache-airflow
to version 2.8.2 or higher.
Overview
apache-airflow is a platform to programmatically author, schedule, and monitor workflows.
Affected versions of this package are vulnerable to Exposure of Resource to Wrong Sphere due to improper permission checks in the API and UI components. An attacker can view DAG code and import errors for DAGs they are not authorized to access by exploiting this vulnerability.
References
CVSS Scores
version 3.1