Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable.
This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification.
Users are recommended to upgrade to 2.8.0, which fixes this issue
This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification.
Users are recommended to upgrade to 2.8.0, which fixes this issue
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
GHSA-5938-79hg-xh3q | Apache Airflow Improper Access Control vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T17:19:40.647Z
Reserved: 2023-12-13T20:48:56.413Z
Link: CVE-2023-50783

No data.

Status : Modified
Published: 2023-12-21T10:15:36.607
Modified: 2024-11-21T08:37:18.497
Link: CVE-2023-50783

No data.

No data.