Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h88f-r7cw-8fv3

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Missing Authentication for Critical Function in Apache Airflow

The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution. This issue affects Apache Airflow >=2.0.0, <2.1.3.

Пакеты

Наименование

apache-airflow

pip
Затронутые версииВерсия исправления

>= 2.0.0, < 2.1.3

2.1.3

EPSS

Процентиль: 100%
0.90036
Критический

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution. This issue affects Apache Airflow >=2.0.0, <2.1.3.

CVSS3: 9.8
debian
больше 4 лет назад

The variable import endpoint was not protected by authentication in Ai ...

EPSS

Процентиль: 100%
0.90036
Критический

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-306