CVE-2023-47037
We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.
Does this matter?
Lower severity and a low EPSS score (1.50%). Track it; it rarely justifies an emergency change on its own.
Description
We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then. Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc. Users should upgrade to version 2.7.3 or later which has removed the vulnerability.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.50% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- apache/airflow
- Source
- security@apache.org
References
- http://www.openwall.com/lists/oss-security/2023/11/12/1Mailing List, Third Party Advisory
- https://github.com/apache/airflow/pull/33413Issue Tracking, Patch
- https://lists.apache.org/thread/04y4vrw1t2xl030gswtctc4nt1w90cb0Mailing List
- http://www.openwall.com/lists/oss-security/2023/11/12/1Mailing List, Third Party Advisory
- https://github.com/apache/airflow/pull/33413Issue Tracking, Patch
- https://lists.apache.org/thread/04y4vrw1t2xl030gswtctc4nt1w90cb0Mailing List
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.