Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-32228

Опубликовано: 18 апр. 2026
Источник: debian
EPSS Низкий

Описание

UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
airflowitppackage

EPSS

Процентиль: 36%
0.00426
Низкий

Связанные уязвимости

CVSS3: 7.5
nvd
4 месяца назад

UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue.

CVSS3: 7.5
github
4 месяца назад

Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions

EPSS

Процентиль: 36%
0.00426
Низкий