CVE-2023-39508
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-200
Revelación de información
Fecha de publicación:
05/08/2023
Última modificación:
13/02/2025
Descripción
*** Pendiente de traducción *** Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Airflow.The "Run Task" feature enables authenticated user to bypass some of the restrictions put in place. It allows to execute code in the webserver context as well as allows to bypas limitation of access the user has to certain DAGs. The "Run Task" feature is considered dangerous and it has been removed entirely in Airflow 2.6.0<br />
<br />
This issue affects Apache Airflow: before 2.6.0.
Impacto
Puntuación base 3.x
8.80
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* | 2.6.0 (excluyendo) |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- http://seclists.org/fulldisclosure/2023/Jul/43
- https://github.com/apache/airflow/pull/29706
- https://lists.apache.org/thread/j2nkjd0zqvtqk85s6ywpx3c35pvzyx15
- http://seclists.org/fulldisclosure/2023/Jul/43
- https://github.com/apache/airflow/pull/29706
- https://lists.apache.org/thread/j2nkjd0zqvtqk85s6ywpx3c35pvzyx15



