PT-2023-4793 · Apache · Apache Airflow

Khoabda

+4

·

Published

2023-08-23

·

Updated

2026-02-20

·

CVE-2023-37379

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 2.7.0
Description The issue is related to insufficient validation of incoming requests, allowing an authenticated user with Connection edit privileges to access connection information and exploit the test connection feature. This can lead to a denial of service (DoS) condition on the server by sending many requests. Malicious actors can also establish harmful connections with the server.
Recommendations For versions prior to 2.7.0, upgrade to version 2.7.0 or newer to mitigate the risk associated with this issue. As a temporary workaround, consider restricting access to the test connection feature until a patch is available. Administrators are encouraged to review and adjust user permissions to restrict access to sensitive functionalities, reducing the attack surface.

Fix

DoS

Resource Exhaustion

SSRF

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-05244
BIT-AIRFLOW-2023-37379
CVE-2023-37379
GHSA-X2MH-8FMC-RQGH
PYSEC-2023-152

Affected Products

Apache Airflow