Описание
In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the --daemon flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local users to expose arbitrary file contents via the webserver.
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListMitigationThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListMitigationVendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListMitigationThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListMitigationVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.3.4 (исключая)
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*
EPSS
Процентиль: 52%
0.00294
Низкий
4.7 Medium
CVSS3
Дефекты
CWE-732
Связанные уязвимости
CVSS3: 4.7
debian
больше 3 лет назад
In Apache Airflow prior to 2.3.4, an insecure umask was configured for ...
EPSS
Процентиль: 52%
0.00294
Низкий
4.7 Medium
CVSS3
Дефекты
CWE-732