PT-2021-17037 · Apache · Apache Airflow
Ian Carroll
·
Published
2021-02-17
·
Updated
2024-03-06
·
CVE-2021-26559
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Apache Airflow version 2.0.0
Description
The issue is related to Improper Access Control on the Configurations Endpoint for the Stable API of Apache Airflow. This allows users with Viewer or User role to obtain Airflow Configurations, including sensitive information, even when the
[webserver] expose config is set to False in airflow.cfg. This vulnerability enabled a privilege escalation attack.Recommendations
For Apache Airflow version 2.0.0, consider restricting access to the Configurations Endpoint to prevent unauthorized users from obtaining sensitive information until a patch is available. As a temporary workaround, review and adjust the
[webserver] expose config setting in airflow.cfg to ensure it is properly configured to restrict access to sensitive configurations.Fix
Improper Privilege Management
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Airflow