Impact
Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that permits an authenticated user who has been granted only task‑level access to view task logs via the externalLogUrl endpoint. This flaw allows the denial of a normal authorization safeguard and results in unintended information disclosure. The vulnerability is classified as CWE‑648, highlighting a weakness in access control enforcement.
Affected Systems
The affected products are Apache Airflow, specifically all releases from version 3.1.0 up to and including 3.1.6. Any instance operating within this version range is susceptible unless configured otherwise or updated to a patched release.
Risk and Exploitability
The flaw carries a medium CVSS score of 6.5 and an EPSS score below 1 %, indicating a low probability of exploitation in the wild. It is not listed in the CISA KEV catalog at present. Exploitation requires an authenticated user who has been granted task‑access permissions, and then the attacker uses the externalLogUrl feature to retrieve log data they would otherwise not be authorized to read.
OpenCVE Enrichment
Github GHSA