Описание
We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.
Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.
Users should upgrade to version 2.7.3 or later which has removed the vulnerability.
Ссылки
- Mailing ListThird Party Advisory
- Issue TrackingPatch
- Mailing List
- Mailing ListThird Party Advisory
- Issue TrackingPatch
- Mailing List
Уязвимые конфигурации
EPSS
4.3 Medium
CVSS3
Дефекты
Связанные уязвимости
We failed to applyCVE-2023-40611 in 2.7.1 and this vulnerability was m ...
Apache Airflow allows authenticated and DAG-view authorized users to modify some DAG run detail values when submitting notes
Уязвимость сетевого программного средства Apache Airflow, связанная с неправильной авторизацией, позволяющая нарушителю изменять произвольные файлы
EPSS
4.3 Medium
CVSS3