Описание
Apache Airflow Improper Access Control vulnerability
Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable. This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification. Users are recommended to upgrade to 2.8.0, which fixes this issue.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-50783
- https://github.com/apache/airflow/pull/33932
- https://github.com/apache/airflow/commit/0e1c106d7cd0703125528a691088e42e17c99929
- https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2023-267.yaml
- https://lists.apache.org/thread/rs7cr3yp726mb89s1m844hy9pq7frgcn
- http://www.openwall.com/lists/oss-security/2023/12/21/4
Пакеты
apache-airflow
< 2.8.0
2.8.0
Связанные уязвимости
Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable. This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification. Users are recommended to upgrade to 2.8.0, which fixes this issue
Apache Airflow, versions before 2.8.0, is affected by a vulnerability ...
Уязвимость программного обеспечения создания, мониторинга и оркестрации сценариев обработки данных Airflow , связанная с недостатками контроля доступа, позволяющая нарушителю получить доступ на изменение данных