We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.  Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.  Users should upgrade to version 2.7.3 or later which has removed the vulnerability.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2023-11-12T13:12:23.137Z

Updated: 2024-09-03T15:23:17.353Z

Reserved: 2023-10-30T10:10:48.025Z

Link: CVE-2023-47037

cve-icon Vulnrichment

Updated: 2024-08-02T21:01:22.230Z

cve-icon NVD

Status : Analyzed

Published: 2023-11-12T14:15:25.980

Modified: 2023-11-20T19:31:24.707

Link: CVE-2023-47037

cve-icon Redhat

No data.