VulnerabilityModified
CVE-2023-42663
Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs.
MEDIUM 6.5EPSS 1.55%
Does this matter?
Lower severity and a low EPSS score (1.55%). Track it; it rarely justifies an emergency change on its own.
Description
Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs. Users of Apache Airflow are advised to upgrade to version 2.7.2 or newer to mitigate the risk associated with this vulnerability.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.55% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apache/airflow
- Source
- security@apache.org
References
- http://www.openwall.com/lists/oss-security/2023/11/12/2Mailing List, Third Party Advisory
- https://github.com/apache/airflow/pull/34315Patch
- https://lists.apache.org/thread/xj86cvfkxgd0cyqfmz6mh1bsfc61c6o9Mailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2023/11/12/2Mailing List, Third Party Advisory
- https://github.com/apache/airflow/pull/34315Patch
- https://lists.apache.org/thread/xj86cvfkxgd0cyqfmz6mh1bsfc61c6o9Mailing List, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.