Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable.
This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification.
Users are recommended to upgrade to 2.8.0, which fixes this issue
This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification.
Users are recommended to upgrade to 2.8.0, which fixes this issue
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5938-79hg-xh3q | Apache Airflow Improper Access Control vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T17:19:40.647Z
Reserved: 2023-12-13T20:48:56.413Z
Link: CVE-2023-50783
No data.
Status : Modified
Published: 2023-12-21T10:15:36.607
Modified: 2024-11-21T08:37:18.497
Link: CVE-2023-50783
No data.
OpenCVE Enrichment
No data.
Github GHSA