CVE-2022-38170
In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local…
Does this matter?
Lower severity and a low EPSS score (0.62%). Track it; it rarely justifies an emergency change on its own.
Description
In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local users to expose arbitrary file contents via the webserver.
- CVSS 3.1
- 4.7 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.62% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- apache/airflow
- Source
- security@apache.org
References
- http://www.openwall.com/lists/oss-security/2022/09/02/12Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/09/02/3Mailing List, Mitigation, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/09/21/2Mailing List, Third Party Advisory
- https://lists.apache.org/thread/zn8mbbb1j2od5nc9zhrvb7rpsrg1vvzvMailing List, Mitigation, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2022/09/02/12Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/09/02/3Mailing List, Mitigation, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/09/21/2Mailing List, Third Party Advisory
- https://lists.apache.org/thread/zn8mbbb1j2od5nc9zhrvb7rpsrg1vvzvMailing List, Mitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.