Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x2mh-8fmc-rqgh

Опубликовано: 23 авг. 2023
Источник: github
Github: Прошло ревью
CVSS4: 7.2
CVSS3: 8.1

Описание

Apache Airflow denial of service vulnerability

Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection edit privileges. This vulnerability allows the user to access connection information and exploit the test connection feature by sending many requests, leading to a denial of service (DoS) condition on the server. Furthermore, malicious actors can leverage this vulnerability to establish harmful connections with the server.

Users of Apache Airflow are strongly advised to upgrade to version 2.7.0 or newer to mitigate the risk associated with this vulnerability. Additionally, administrators are encouraged to review and adjust user permissions to restrict access to sensitive functionalities, reducing the attack surface.

Пакеты

Наименование

apache-airflow

pip
Затронутые версииВерсия исправления

< 2.7.0b1

2.7.0b1

EPSS

Процентиль: 46%
0.00233
Низкий

7.2 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-200
CWE-400
CWE-918

Связанные уязвимости

CVSS3: 8.1
nvd
больше 2 лет назад

Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection edit privileges. This vulnerability allows the user to access connection information and exploit the test connection feature by sending many requests, leading to a denial of service (DoS) condition on the server. Furthermore, malicious actors can leverage this vulnerability to establish harmful connections with the server. Users of Apache Airflow are strongly advised to upgrade to version 2.7.0 or newer to mitigate the risk associated with this vulnerability. Additionally, administrators are encouraged to review and adjust user permissions to restrict access to sensitive functionalities, reducing the attack surface.

CVSS3: 8.1
debian
больше 2 лет назад

Apache Airflow, in versions prior to 2.7.0, contains a security vulner ...

CVSS3: 8.1
fstec
больше 2 лет назад

Уязвимость программного обеспечения создания, мониторинга и оркестрации сценариев обработки данных Airflow, связанная с недостаточной проверкой поступающих запросов, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

EPSS

Процентиль: 46%
0.00233
Низкий

7.2 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-200
CWE-400
CWE-918