PT-2021-17037 · Apache · Apache Airflow

Ian Carroll

·

Published

2021-02-17

·

Updated

2024-03-06

·

CVE-2021-26559

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Airflow version 2.0.0
Description The issue is related to Improper Access Control on the Configurations Endpoint for the Stable API of Apache Airflow. This allows users with Viewer or User role to obtain Airflow Configurations, including sensitive information, even when the [webserver] expose config is set to False in airflow.cfg. This vulnerability enabled a privilege escalation attack.
Recommendations For Apache Airflow version 2.0.0, consider restricting access to the Configurations Endpoint to prevent unauthorized users from obtaining sensitive information until a patch is available. As a temporary workaround, review and adjust the [webserver] expose config setting in airflow.cfg to ensure it is properly configured to restrict access to sensitive configurations.

Fix

Improper Privilege Management

Improper Access Control

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2021-26559
CVE-2021-26559
GHSA-FFW3-6MP6-JMVJ
PYSEC-2021-2

Affected Products

Apache Airflow