CVE-2021-45230
published 2022-01-20CVE-2021-45230: In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags…
PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
1.71%
74.6th percentile
In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | 1.10.0 – 1.10.15 | — |
| apache | airflow | >= 2.0.0 < 2.2.0 | 2.2.0 |
| apache_software_foundation | apache_airflow | — | — |
| apache_software_foundation | apache_airflow | >= Apache Airflow 2 < 2.2.0 | 2.2.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Privilege Management in apache-airflow
ghsa·2022-01-28
CVE-2021-45230 [MEDIUM] CWE-269 Improper Privilege Management in apache-airflow
Improper Privilege Management in apache-airflow
In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for.
OSV
Improper Privilege Management in apache-airflow
osv·2022-01-28
CVE-2021-45230 [MEDIUM] Improper Privilege Management in apache-airflow
Improper Privilege Management in apache-airflow
In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for.
OSV
CVE-2021-45230: In Apache Airflow prior to 2
osv·2022-01-20
CVE-2021-45230 CVE-2021-45230: In Apache Airflow prior to 2
In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-01-20
Published