PT-2021-21067 · Apache · Apache Airflow

Dolev Farhi

·

Published

2021-08-16

·

Updated

2024-03-06

·

CVE-2021-35936

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Apache Airflow versions prior to 2.1.2
Description: The issue affects the logging server in Apache Airflow, which has no authentication and allows reading log files of DAG jobs when remote logging is not used. This could potentially expose sensitive information.
Recommendations: For versions prior to 2.1.2, update to version 2.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the logging server or disabling it when not in use to minimize the risk of exploitation.

Fix

Missing Authorization

Information Disclosure

Missing Authentication

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2021-35936
CVE-2021-35936
GHSA-M6H2-JX9V-58W6
PYSEC-2021-122

Affected Products

Apache Airflow