Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc. Users should upgrade to version 2.7.1 or later which has removed the vulnerability.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2023-09-12T11:05:22.841Z

Updated: 2024-08-02T18:38:50.988Z

Reserved: 2023-08-17T14:01:13.240Z

Link: CVE-2023-40611

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-09-12T12:15:08.200

Modified: 2024-01-16T14:14:18.937

Link: CVE-2023-40611

cve-icon Redhat

No data.