|
Message-ID: <16f05379-b48d-bdbe-ba77-367e6c01fa9e@apache.org> Date: Tue, 11 Jul 2023 15:15:49 +0000 From: Ephraim Anierobi <ephraimanierobi@...che.org> To: oss-security@...ts.openwall.com Subject: CVE-2023-35908: Apache Airflow: Access to DAGs without relevant permission Severity: low Affected versions: - Apache Airflow before 2.6.3 Description: Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommended to upgrade to a version that is not affected Credit: Name : Karthikeyan Singaravelan Employer : Visa (finder) References: https://github.com/apache/airflow/pull/32014 https://airflow.apache.org/ https://www.cve.org/CVERecord?id=CVE-2023-35908
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.