Описание
Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with custom permissions limited to task access to view task logs without having task log access.
Users are recommended to upgrade to Apache Airflow 3.1.7 or later, which resolves this issue.
Ссылки
- Issue TrackingPatch
- Mailing ListVendor Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 3.1.0 (включая) до 3.1.7 (исключая)
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*
EPSS
Процентиль: 13%
0.00043
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-648
Связанные уязвимости
CVSS3: 6.5
debian
около 2 месяцев назад
Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization f ...
CVSS3: 6.5
github
около 2 месяцев назад
Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access
EPSS
Процентиль: 13%
0.00043
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-648