VYPR

CWE-1056

Invokable Control Element with Variadic Parameters

BaseIncomplete

Description

A named-callable or method control element has a signature that supports a variable (variadic) number of parameters or arguments.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1)

  • CVE-2020-13927KEVNov 10, 2020
    risk 0.16cvss epss 1.00

    The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and is documented at…