VYPR
High severity8.1NVD Advisory· Published Mar 14, 2024· Updated Jun 17, 2026

CVE-2024-28746

CVE-2024-28746

Description

Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access.

Users of Apache Airflow are recommended to upgrade to version 2.8.3 or newer to mitigate the risk associated with this vulnerability

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
apache-airflowPyPI
>= 2.8.0, < 2.8.3rc12.8.3rc1

Affected products

4
  • Apache/Airflow2 versions
    cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*range: >=2.8.0,<2.8.3
    • (no CPE)range: 2.8.0
  • osv-coords2 versions
    >= 2.8.0, < 2.8.3+ 1 more
    • (no CPE)range: >= 2.8.0, < 2.8.3
    • (no CPE)range: >= 2.8.0, < 2.8.3rc1

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.