Количество 4
Количество 4
CVE-2023-39508
Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Airflow.The "Run Task" feature enables authenticated user to bypass some of the restrictions put in place. It allows to execute code in the webserver context as well as allows to bypas limitation of access the user has to certain DAGs. The "Run Task" feature is considered dangerous and it has been removed entirely in Airflow 2.6.0 This issue affects Apache Airflow: before 2.6.0.
CVE-2023-39508
Execution with Unnecessary Privileges, : Exposure of Sensitive Informa ...
GHSA-269x-pg5c-5xgm
Apache Airflow Execution with Unnecessary Privileges
BDU:2023-05231
Уязвимость функции Run Task программного обеспечения создания, мониторинга и оркестрации сценариев обработки данных Airflow, позволяющая нарушителю получить доступ к конфиденциальной информации
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-39508 Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Airflow.The "Run Task" feature enables authenticated user to bypass some of the restrictions put in place. It allows to execute code in the webserver context as well as allows to bypas limitation of access the user has to certain DAGs. The "Run Task" feature is considered dangerous and it has been removed entirely in Airflow 2.6.0 This issue affects Apache Airflow: before 2.6.0. | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
CVE-2023-39508 Execution with Unnecessary Privileges, : Exposure of Sensitive Informa ... | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
GHSA-269x-pg5c-5xgm Apache Airflow Execution with Unnecessary Privileges | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
BDU:2023-05231 Уязвимость функции Run Task программного обеспечения создания, мониторинга и оркестрации сценариев обработки данных Airflow, позволяющая нарушителю получить доступ к конфиденциальной информации | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад |
Уязвимостей на страницу