User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-gp5f-cx7h-8q6f Apache Airflow's create action can upsert existing Pools/Connections/Variables
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 30 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache airflow
Vendors & Products Apache
Apache airflow

Thu, 30 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
References

Thu, 30 Oct 2025 09:30:00 +0000

Type Values Removed Values Added
Description User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.
Title Apache Airflow: Privilege boundary bypass in bulk APIs (create action can upsert existing Pools/Connections/Variables)
Weaknesses CWE-250
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-10-30T14:25:43.960Z

Reserved: 2025-10-15T14:08:45.584Z

Link: CVE-2025-62503

cve-icon Vulnrichment

Updated: 2025-10-30T10:05:06.911Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-30T10:15:35.790

Modified: 2025-10-30T15:15:42.187

Link: CVE-2025-62503

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-30T14:37:25Z