SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-50944

Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don't have access.

MEDIUM 6.5EPSS 0.98%

Does this matter?

Lower severity and a low EPSS score (0.98%). Track it; it rarely justifies an emergency change on its own.

Description

Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don't have access. This vulnerability is considered low since it requires an authenticated user to exploit it. Users are recommended to upgrade to version 2.8.1, which fixes this issue.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.98% probability · 60th percentile
CISA KEV
Not listed
Weakness
CWE-862
Affected
apache/airflow
Source
security@apache.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.