We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-39508

Apache Airflow: Airflow "Run task" feature allows execution with unnecessary priviledges



Assignerapache
Reserved2023-08-03
Published2023-08-05
Updated2024-10-02

Description

Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Airflow.The "Run Task" feature enables authenticated user to bypass some of the restrictions put in place. It allows to execute code in the webserver context as well as allows to bypas limitation of access the user has to certain DAGs. The "Run Task" feature is considered dangerous and it has been removed entirely in Airflow 2.6.0 This issue affects Apache Airflow: before 2.6.0.

Problem types

CWE-250: Execution with Unnecessary Privileges

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Product status

Default status
unaffected

Any version before 2.6.0
affected

Credits

balis0ng 0x40075393e0

References

https://github.com/apache/airflow/pull/29706 patch

https://lists.apache.org/thread/j2nkjd0zqvtqk85s6ywpx3c35pvzyx15 vendor-advisory

http://seclists.org/fulldisclosure/2023/Jul/43

cve.org CVE-2023-39508

nvd.nist.gov CVE-2023-39508

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.