Логотип exploitDog
bind:CVE-2021-38540
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-38540

Количество 3

Количество 3

nvd логотип

CVE-2021-38540

больше 4 лет назад

The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution. This issue affects Apache Airflow >=2.0.0, <2.1.3.

CVSS3: 9.8
EPSS: Высокий
debian логотип

CVE-2021-38540

больше 4 лет назад

The variable import endpoint was not protected by authentication in Ai ...

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-h88f-r7cw-8fv3

больше 3 лет назад

Missing Authentication for Critical Function in Apache Airflow

CVSS3: 9.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-38540

The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution. This issue affects Apache Airflow >=2.0.0, <2.1.3.

CVSS3: 9.8
90%
Высокий
больше 4 лет назад
debian логотип
CVE-2021-38540

The variable import endpoint was not protected by authentication in Ai ...

CVSS3: 9.8
90%
Высокий
больше 4 лет назад
github логотип
GHSA-h88f-r7cw-8fv3

Missing Authentication for Critical Function in Apache Airflow

CVSS3: 9.8
90%
Высокий
больше 3 лет назад

Уязвимостей на страницу