Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 PyPI

Apache Airflow Improper Access Control vulnerability

GHSA-5938-79hg-xh3q · BIT-airflow-2023-50783 · CVE-2023-50783 · PYSEC-2023-267

Published · Modified

Description

Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable.
This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification.
Users are recommended to upgrade to 2.8.0, which fixes this issue.

Ready to move

Start Securing

Free, no credit card | First findings in minutes