PT-2023-4783 · Apache · Apache Airflow

Balis0Ng

·

Published

2023-08-04

·

Updated

2026-02-20

·

CVE-2023-39508

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 2.6.0
Description The issue is related to the "Run Task" feature in Apache Airflow, which allows an authenticated user to bypass some restrictions and execute code in the webserver context, as well as access certain DAGs beyond their limitations. This feature is considered dangerous and has been removed entirely in Airflow 2.6.0. The vulnerability can lead to exposure of sensitive information to unauthorized actors.
Recommendations For Apache Airflow versions prior to 2.6.0, consider updating to version 2.6.0 or later, where the "Run Task" feature has been removed entirely. As a temporary workaround, consider disabling the "Run Task" feature to minimize the risk of exploitation. Restrict access to the webserver context and certain DAGs to prevent unauthorized access.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2023-05231
BIT-AIRFLOW-2023-39508
CVE-2023-39508
GHSA-269X-PG5C-5XGM
PYSEC-2023-134

Affected Products

Apache Airflow