CVE-2024-27906
Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not have permission to view through the API and the UI.
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not have permission to view through the API and the UI. Users of Apache Airflow are recommended to upgrade to version 2.8.2 or newer to mitigate the risk associated with this vulnerability
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 0.34% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- apache/airflow
- Source
- security@apache.org
References
- https://github.com/apache/airflow/pull/37290Broken Link
- https://github.com/apache/airflow/pull/37468Issue Tracking
- https://lists.apache.org/thread/on4f7t5sqr3vfgp1pvkck79wv7mq9st5Mailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2024/02/29/1Mailing List
- https://github.com/apache/airflow/pull/37290Broken Link
- https://github.com/apache/airflow/pull/37468Issue Tracking
- https://lists.apache.org/thread/on4f7t5sqr3vfgp1pvkck79wv7mq9st5Mailing List, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.