Apache Airflow, versions before 2.6.3, has a vulnerability where an authenticated user can use crafted input to make the current request hang. It is recommended to upgrade to a version that is not affected
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0012 | Apache Airflow, versions before 2.6.3, has a vulnerability where an authenticated user can use crafted input to make the current request hang. It is recommended to upgrade to a version that is not affected |
Github GHSA |
GHSA-3h4m-m55v-gx4m | Apache Airflow Improper Input Validation vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 04 Oct 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-10-04T13:47:18.046Z
Reserved: 2023-06-23T00:31:48.279Z
Link: CVE-2023-36543
Updated: 2024-08-02T16:52:53.133Z
Status : Modified
Published: 2023-07-12T10:15:10.157
Modified: 2024-11-21T08:09:54.447
Link: CVE-2023-36543
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA