Vulnerability CVE-2024-27906


Published: 2024-02-29

Description:
Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not have permission to view through the API and the UI.

Users of Apache Airflow are recommended to upgrade to version 2.8.2 or newer to mitigate the risk associated with this vulnerability

Type:

CWE-668

(Exposure of Resource to Wrong Sphere)

 References:
https://github.com/apache/airflow/pull/37290
https://github.com/apache/airflow/pull/37468
https://lists.apache.org/thread/on4f7t5sqr3vfgp1pvkck79wv7mq9st5

Copyright 2024, cxsecurity.com

 

Back to Top