VYPR

PyPI package

apache-airflow

pkg:pypi/apache-airflow

Vulnerabilities (111)

  • CVE-2023-50943Jan 24, 2024
    affected < 2.8.1rc1fixed 2.8.1rc1

    Apache Airflow, versions before 2.8.1, have a vulnerability that allows a potential attacker to poison the XCom data by bypassing the protection of "enable_xcom_pickling=False" configuration setting resulting in poisoned data after XCom deserialization. This vulnerability is cons

  • CVE-2023-51702Jan 24, 2024
    affected >= 2.3.0, < 2.6.1fixed 2.6.1

    Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any encryption. Additionally,

  • CVE-2023-48291Dec 21, 2023
    affected < 2.8.0fixed 2.8.0

    Apache Airflow, in versions prior to 2.8.0, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could give the user write access to various DAG resources for DAGs that the user had no access to, thus, enabl

  • CVE-2023-50783Dec 21, 2023
    affected < 2.8.0fixed 2.8.0

    Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable. This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification. U

  • CVE-2023-47265Dec 21, 2023
    affected >= 2.6.0, < 2.8.0b1fixed 2.8.0b1

    Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded and not-sanitized javascript in the parameter description field of the DAG. This Javascript can be executed on the client side of any of the user who looks at

  • CVE-2023-49920Dec 21, 2023
    affected >= 2.7.0, < 2.8.0fixed 2.8.0

    Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. As a result, it was possible for a malicious website opened in the same browser - by the user who also had Airflow UI opened - to tr

  • CVE-2023-42781Nov 12, 2023
    affected < 2.7.3fixed 2.7.3

    Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs.  This is a different issue than CVE-2023-42663 but leading to similar outcome. Users of Apa

  • CVE-2023-47037Nov 12, 2023
    affected < 2.7.3fixed 2.7.3

    We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.  Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes.

  • CVE-2023-46215Oct 28, 2023
    affected >= 1.10.0, < 2.7.0fixed 2.7.0

    Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow. Sensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend Note: the vulnerability is about the information expose

  • CVE-2023-46288Oct 23, 2023
    affected >= 2.4.0, < 2.7.2fixed 2.7.2

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.4.0 to 2.7.0. Sensitive configuration information has been exposed to authenticated users with the ability to read configuration via Airflow REST A

  • CVE-2023-42663Oct 14, 2023
    affected < 2.7.2fixed 2.7.2

    Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs. Users of Apache Airflow are advised to upgrade to version 2.7.2 or newer to mitigate the ri

  • CVE-2023-42792Oct 14, 2023
    affected < 2.7.2fixed 2.7.2

    Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could give the user write access to various DAG resources for DAGs that the user had no access to, thus, enabl

  • CVE-2023-45348Oct 14, 2023
    affected >= 2.7.0, < 2.7.2fixed 2.7.2

    Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the "expose_config" option is set to "non-sensitive-only". The `expose_config` option is False by default. It is recomme

  • CVE-2023-42780Oct 14, 2023
    affected < 2.7.2fixed 2.7.2

    Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that allows authenticated users of Airflow to list warnings for all DAGs, even if the user had no permission to see those DAGs. It would reveal the dag_ids and the stack-traces of import errors for those D

  • CVE-2023-40712Sep 12, 2023
    affected < 2.7.1fixed 2.7.1

    Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be masked in the UI. Users

  • CVE-2023-40611Sep 12, 2023
    affected < 2.7.1fixed 2.7.1

    Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc. Users s

  • CVE-2023-39441Aug 23, 2023
    affected < 2.7.0fixed 2.7.0

    Apache Airflow SMTP Provider before 1.3.0, Apache Airflow IMAP Provider before 3.3.0, and Apache Airflow before 2.7.0 are affected by the Validation of OpenSSL Certificate vulnerability. The default SSL context with SSL library did not check a server's X.509 certificate.  Instea

  • CVE-2023-37379Aug 23, 2023
    affected < 2.7.0b1fixed 2.7.0b1

    Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection edit privileges. This vulnerability allows the user to access connection information and exploit the test connection feature by sendi

  • CVE-2023-40273Aug 23, 2023
    affected < 2.7.0rc2fixed 2.7.0rc2

    The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the password of the user has been reset by the admin - up until the expiry of the session of the user. Other than manually cleaning the session database (for datab

  • CVE-2023-39508Aug 5, 2023
    affected < 2.6.0b1fixed 2.6.0b1

    Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Airflow.The "Run Task" feature enables authenticated user to bypass some of the restrictions put in place. It allows to execute c

Page 3 of 6