Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3q8r-f3pj-3gc4

Опубликовано: 07 окт. 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.6
CVSS3: 8.1

Описание

Apache Airflow may allow authenticated users who have been deactivated to continue using the UI or API

In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API.

Пакеты

Наименование

apache-airflow

pip
Затронутые версииВерсия исправления

< 2.4.1rc1

2.4.1rc1

EPSS

Процентиль: 56%
0.00339
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-285
CWE-613

Связанные уязвимости

CVSS3: 8.1
nvd
больше 3 лет назад

In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API.

CVSS3: 8.1
debian
больше 3 лет назад

In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn' ...

EPSS

Процентиль: 56%
0.00339
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-285
CWE-613