PT-2023-4014 · Apache · Apache Airflow

·

CVE-2023-35908

·

Published

2023-07-11

·

Updated

2026-02-20

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 2.6.3
Description The issue is related to improper authorization in Apache Airflow, allowing unauthorized read access to a DAG through a specially crafted URL. This could enable a remote attacker to disclose protected information.
Recommendations For versions prior to 2.6.3, upgrade to a version that is not affected to resolve the issue. As a temporary workaround, consider restricting access to the DAGs through the URL to minimize the risk of exploitation.

Exploit

Fix

DoS

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-04312
BIT-AIRFLOW-2023-35908
CVE-2023-35908
GHSA-2H84-3CRQ-VGFJ
PYSEC-2023-119

Affected Products

Apache Airflow