Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.

Users should upgrade to version 2.7.1 or later which has removed the vulnerability.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-0018 Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc. Users should upgrade to version 2.7.1 or later which has removed the vulnerability.
Github GHSA Github GHSA GHSA-wpg8-mf6h-gm92 Apache Airflow Incorrect Authorization vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 25 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Description Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc. Users should upgrade to version 2.7.1 or later which has removed the vulnerability. Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc. Users should upgrade to version 2.7.1 or later which has removed the vulnerability.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-06-25T13:39:24.245Z

Reserved: 2023-08-17T14:01:13.240Z

Link: CVE-2023-40611

cve-icon Vulnrichment

Updated: 2024-08-02T18:38:50.988Z

cve-icon NVD

Status : Modified

Published: 2023-09-12T12:15:08.200

Modified: 2025-06-25T14:15:21.987

Link: CVE-2023-40611

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.