CVE-2022-38170
published 2022-09-02CVE-2022-38170: In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in…
PriorityP423medium4.7CVSS 3.1
AVLACHPRLUINSUCHINAN
EPSS
0.59%
44.2th percentile
In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local users to expose arbitrary file contents via the webserver.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | < 2.3.4 | 2.3.4 |
| apache_software_foundation | apache_airflow | Apache Airflow – 2.3.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Airflow exposes arbitrary file content
osv·2022-09-03
CVE-2022-38170 [MEDIUM] Apache Airflow exposes arbitrary file content
Apache Airflow exposes arbitrary file content
In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local users to expose arbitrary file contents via the webserver.
GHSA
Apache Airflow exposes arbitrary file content
ghsa·2022-09-03
CVE-2022-38170 [MEDIUM] CWE-362 Apache Airflow exposes arbitrary file content
Apache Airflow exposes arbitrary file content
In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local users to expose arbitrary file contents via the webserver.
OSV
CVE-2022-38170: In Apache Airflow prior to 2
osv·2022-09-02
CVE-2022-38170 CVE-2022-38170: In Apache Airflow prior to 2
In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local users to expose arbitrary file contents via the webserver.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/09/02/12http://www.openwall.com/lists/oss-security/2022/09/02/3http://www.openwall.com/lists/oss-security/2022/09/21/2https://lists.apache.org/thread/zn8mbbb1j2od5nc9zhrvb7rpsrg1vvzvhttp://www.openwall.com/lists/oss-security/2022/09/02/12http://www.openwall.com/lists/oss-security/2022/09/02/3http://www.openwall.com/lists/oss-security/2022/09/21/2https://lists.apache.org/thread/zn8mbbb1j2od5nc9zhrvb7rpsrg1vvzv
2022-09-02
Published