Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ffw3-6mp6-jmvj

Опубликовано: 07 апр. 2021
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Improper Access Control in Apache Airflow

Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when [webserver] expose_config is set to False in airflow.cfg. This allowed a privilege escalation attack. This issue affects Apache Airflow 2.0.0.

Пакеты

Наименование

apache-airflow

pip
Затронутые версииВерсия исправления

= 2.0.0

2.0.1rc1

EPSS

Процентиль: 68%
0.00557
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-269
CWE-284

Связанные уязвимости

CVSS3: 6.5
nvd
почти 5 лет назад

Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow.cfg`. This allowed a privilege escalation attack. This issue affects Apache Airflow 2.0.0.

CVSS3: 6.5
debian
почти 5 лет назад

Improper Access Control on Configurations Endpoint for the Stable API ...

EPSS

Процентиль: 68%
0.00557
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-269
CWE-284