Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.
Users should upgrade to version 2.7.1 or later which has removed the vulnerability.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2023-09-12T11:05:22.841Z
Updated: 2024-08-02T18:38:50.988Z
Reserved: 2023-08-17T14:01:13.240Z
Link: CVE-2023-40611
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-09-12T12:15:08.200
Modified: 2024-11-21T08:19:49.560
Link: CVE-2023-40611
Redhat
No data.