CVE-2024-28746

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/03/2024
Last modified:
20/03/2025

Description

Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access. <br /> <br /> Users of Apache Airflow are recommended to upgrade to version 2.8.3 or newer to mitigate the risk associated with this vulnerability

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* 2.8.0 (including) 2.8.3 (excluding)