Severity: low

Affected versions:

- Apache Airflow before 2.7.2

Description:

Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that 
allows authenticated users of Airflow to list warnings for all DAGs, even if 
the user had no permission to see those DAGs. It would reveal the dag_ids and 
the stack-traces of import errors for those DAGs with import errors.
Users of Apache Airflow are advised to upgrade to version 2.7.2 or newer to 
mitigate the risk associated with this vulnerability.

Credit:

balis0ng (finder)
Hussein Awala (remediation developer)

References:

https://github.com/apache/airflow/pull/34355
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2023-42780

Reply via email to