ID:9341 - Exploit for Improper Authentication in Apache Airflow - CVE-2020-13927

 
Main Vulnerability Database Exploits ID:9341 - Exploit for Improper Authentication in Apache Airflow - CVE-2020-13927

ID:9341 - Exploit for Improper Authentication in Apache Airflow - CVE-2020-13927

Published: September 19, 2023


Vulnerability identifier: #VU64047
Vulnerability risk: High
CVE-ID: CVE-2020-13927
CWE-ID: CWE-287
Exploitation vector: Remote access
Vulnerable software:
Apache Airflow

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to default setting for Airflow's Experimental API allow all API requests to be performed without authentication. A remote non-authenticated attacker can perform arbitrary API actions and eventually compromise the affected system.


Remediation

Install updates from vendor's website.