Improper access control in Apache Airflow - CVE-2024-26280
Published: March 4, 2024
Vulnerability identifier: #VU86995
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-26280
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user with access to Ops and Viewers can view all information on audit logs, including dag names and usernames they were not permitted to view.
Affected software
Apache Airflow
How to mitigate CVE-2024-26280
Install updates from vendor's website.
Apache Airflow - update to 2.8.2