Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-47037

Опубликовано: 12 нояб. 2023
Источник: debian

Описание

We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.  Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.  Users should upgrade to version 2.7.3 or later which has removed the vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
airflowitppackage

Связанные уязвимости

CVSS3: 4.3
nvd
около 2 лет назад

We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.  Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.  Users should upgrade to version 2.7.3 or later which has removed the vulnerability.

CVSS3: 4.3
github
около 2 лет назад

Apache Airflow allows authenticated and DAG-view authorized users to modify some DAG run detail values when submitting notes

CVSS3: 4.3
fstec
около 2 лет назад

Уязвимость сетевого программного средства Apache Airflow, связанная с неправильной авторизацией, позволяющая нарушителю изменять произвольные файлы