Логотип exploitDog
bind:CVE-2026-30911
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-30911

Количество 3

Количество 3

nvd логотип

CVE-2026-30911

13 дней назад

Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, approve, or reject HITL workflows belonging to any other task instance. Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-30911

13 дней назад

Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vuln ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-8x34-9q3v-h7g8

13 дней назад

Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-30911

Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, approve, or reject HITL workflows belonging to any other task instance. Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.

CVSS3: 8.1
0%
Низкий
13 дней назад
debian логотип
CVE-2026-30911

Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vuln ...

CVSS3: 8.1
0%
Низкий
13 дней назад
github логотип
GHSA-8x34-9q3v-h7g8

Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization

CVSS3: 8.1
0%
Низкий
13 дней назад

Уязвимостей на страницу