Improper access control in Apache Airflow - CVE-2024-26280

 

Improper access control in Apache Airflow - CVE-2024-26280

Published: March 4, 2024


Vulnerability identifier: #VU86995
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-26280
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A remote user with access to Ops and Viewers can view all information on audit logs, including dag names and usernames they were not permitted to view.


Affected software

Apache Airflow

How to mitigate CVE-2024-26280

Install updates from vendor's website.

Apache Airflow - update to 2.8.2

External References

Related Security Bulletins