VYPR

Airflow

by Apache

pypi: airflow

Source repositories

CVEs (174)

  • CVE-2023-40712MedSep 12, 2023
    risk 0.35cvss 6.5epss 0.01

    Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be masked in the UI. …

  • CVE-2023-36543MedJul 12, 2023
    risk 0.35cvss 6.5epss 0.02

    Apache Airflow, versions before 2.6.3, has a vulnerability where an authenticated user can use crafted input to make the current request hang. It is recommended to upgrade to a version that is not affected

  • CVE-2023-35908MedJul 12, 2023
    risk 0.35cvss 6.5epss 0.01

    Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommended to upgrade to a version that is not affected

  • CVE-2023-22888MedJul 12, 2023
    risk 0.35cvss 6.5epss 0.01

    Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to cause a service disruption by manipulating the run_id parameter. This vulnerability is considered low since it requires an authenticated user to exploit it. It is recommended to…

  • CVE-2023-22887MedJul 12, 2023
    risk 0.35cvss 6.5epss 0.02

    Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to perform unauthorized file access outside the intended directory structure by manipulating the run_id parameter. This vulnerability is considered low since it requires an…

  • CVE-2022-46651MedJul 12, 2023
    risk 0.35cvss 6.5epss 0.01

    Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Connection edit view. This vulnerability is considered low since it requires someone with access to Connection resources…

  • CVE-2023-35005MedJun 19, 2023
    risk 0.35cvss 6.5epss 0.02

    In Apache Airflow, some potentially sensitive values were being shown to the user in certain situations. This vulnerability is mitigated by the fact configuration is not shown in the UI by default (only if `[webserver] expose_config` is set to `non-sensitive-only`), and not all…

  • CVE-2021-26559MedFeb 17, 2021
    risk 0.35cvss 6.5epss 0.03

    Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow.cfg`. This allowed a…

  • CVE-2020-17511MedDec 14, 2020
    risk 0.35cvss 6.5epss 0.03

    In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in the Log table in Airflow Metadatase. Same happened when creating a Connection with a password field.

  • CVE-2020-13944MedSep 17, 2020
    risk 0.35cvss 6.1epss 0.25

    In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit.

  • CVE-2020-11983MedJul 17, 2020
    risk 0.35cvss 5.4epss 0.02

    An issue was found in Apache Airflow versions 1.10.10 and below. It was discovered that many of the admin management screens in the new/RBAC UI handled escaping incorrectly, allowing authenticated users with appropriate permissions to create stored XSS attacks.

  • CVE-2021-28359MedMay 2, 2021
    risk 0.34cvss 6.1epss 0.14

    The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions <1.10.15 in 1.x series and affects 2.0.0 and 2.0.1 and 2.x series. This is the same as CVE-2020-13944 & CVE-2020-17515 but the…

  • CVE-2020-17515MedDec 11, 2020
    risk 0.34cvss 6.1epss 0.16

    The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions prior to 1.10.13. This is same as CVE-2020-13944 but the implemented fix in Airflow 1.10.13 did not fix the issue completely.

  • CVE-2024-41937MedAug 21, 2024
    risk 0.33cvss 6.1epss 0.02

    Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider to be installed on the web server and the user…

  • CVE-2022-43985MedNov 2, 2022
    risk 0.33cvss 6.1epss 0.02

    In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint.

  • CVE-2022-43982MedNov 2, 2022
    risk 0.33cvss 6.1epss 0.01

    In Apache Airflow versions prior to 2.4.2, the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument.

  • CVE-2022-40754MedSep 21, 2022
    risk 0.33cvss 6.1epss 0.02

    In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint.

  • CVE-2021-45229MedFeb 25, 2022
    risk 0.33cvss 6.1epss 0.03

    It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache Airflow versions 2.2.3 and below.

  • CVE-2017-12614MedAug 6, 2018
    risk 0.33cvss 6.1epss 0.02

    It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is…

  • CVE-2026-49267MedJun 1, 2026
    risk 0.31cvss 5.9epss 0.00

    Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections without verifying the remote certificate when the deployment used `[email] smtp_starttls=True` without `[email] smtp_ssl`. An attacker positioned between the…

Page 6 of 9