PT-2023-8623 · Apache · Apache Airflow
Happyhacking
·
Published
2023-09-12
·
Updated
2026-02-20
·
CVE-2023-40611
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Apache Airflow versions before 2.7.1
Description
The issue allows authenticated and DAG-view authorized users to modify some DAG run detail values when submitting notes, potentially altering details such as configuration parameters and start dates.
Recommendations
For Apache Airflow versions before 2.7.1, users should upgrade to version 2.7.1 or later, which has removed the vulnerability.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow