Medium severity4.3NVD Advisory· Published Sep 12, 2023· Updated Jun 17, 2026
CVE-2023-40611
CVE-2023-40611
Description
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.
Users should upgrade to version 2.7.1 or later which has removed the vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-airflowPyPI | < 2.7.1 | 2.7.1 |
Affected products
4- osv-coords2 versions
< 2.7.3+ 1 more
- (no CPE)range: < 2.7.3
- (no CPE)range: < 2.7.1
Patches
Vulnerability mechanics
References
8- github.com/apache/airflow/pull/33413nvdPatchVendor AdvisoryWEB
- www.openwall.com/lists/oss-security/2023/11/12/1nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-wpg8-mf6h-gm92ghsaADVISORY
- lists.apache.org/thread/8y9xk1s3j4qr36yzqn8ogbn9fl7pxrn0nvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-40611ghsaADVISORY
- github.com/apache/airflow/commit/2a0106e4edf67c5905ebfcb82a6008662ae0f7adghsaWEB
- github.com/apache/airflow/commit/b7a46c970d638028a4a7643ad000dcee951fb9efghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2023-170.yamlghsaWEB
News mentions
0No linked articles in our index yet.