Bug 2238617 (CVE-2023-40611) - CVE-2023-40611 Apache Airflow: Dag Runs Broken Access Control Vulnerability
Summary: CVE-2023-40611 Apache Airflow: Dag Runs Broken Access Control Vulnerability
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2023-40611
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2238618
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-09-12 20:47 UTC by Marco Benatto
Modified: 2023-09-12 20:47 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2023-09-12 20:47:56 UTC
Embargoed:


Attachments (Terms of Use)

Description Marco Benatto 2023-09-12 20:47:20 UTC
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.

Users should upgrade to version 2.7.1 or later which has removed the vulnerability.

https://lists.apache.org/thread/8y9xk1s3j4qr36yzqn8ogbn9fl7pxrn0
https://github.com/apache/airflow/pull/33413

Comment 1 Marco Benatto 2023-09-12 20:47:34 UTC
Created golang-cloud-google tracking bugs for this issue:

Affects: fedora-all [bug 2238618]


Note You need to log in before you can comment on or make changes to this bug.