CVE-2023-40611
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes.
Does this matter?
Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.
Description
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc. Users should upgrade to version 2.7.1 or later which has removed the vulnerability.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- apache/airflow
- Source
- security@apache.org
References
- http://www.openwall.com/lists/oss-security/2023/11/12/1Mailing List, Third Party Advisory
- https://github.com/apache/airflow/pull/33413Patch, Vendor Advisory
- https://lists.apache.org/thread/8y9xk1s3j4qr36yzqn8ogbn9fl7pxrn0Mailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2023/11/12/1Mailing List, Third Party Advisory
- https://github.com/apache/airflow/pull/33413Patch, Vendor Advisory
- https://lists.apache.org/thread/8y9xk1s3j4qr36yzqn8ogbn9fl7pxrn0Mailing List, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.