CVE-2023-40611
published 2023-09-12CVE-2023-40611: Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail…
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
1.31%
67.2th percentile
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.
Users should upgrade to version 2.7.1 or later which has removed the vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | < 2.7.3 | 2.7.3 |
| apache_software_foundation | apache_airflow | < 2.7.3 | 2.7.3 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
osv4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-47037: We failed to apply CVE-2023-40611 in 2
osv·2023-11-12·CVSS 4.3
CVE-2023-47037 [MEDIUM] CVE-2023-47037: We failed to apply CVE-2023-40611 in 2
We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.
Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.
Users should upgrade to version 2.7.3 or later which has removed the vulnerability.
GHSA
Apache Airflow Incorrect Authorization vulnerability
ghsa·2023-09-12
CVE-2023-40611 [MEDIUM] CWE-863 Apache Airflow Incorrect Authorization vulnerability
Apache Airflow Incorrect Authorization vulnerability
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.
Users should upgrade to version 2.7.1 or later which has removed the vulnerability.
OSV
CVE-2023-40611: Apache Airflow, versions before 2
osv·2023-09-12
CVE-2023-40611 CVE-2023-40611: Apache Airflow, versions before 2
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.
Users should upgrade to version 2.7.1 or later which has removed the vulnerability.
OSV
Apache Airflow Incorrect Authorization vulnerability
osv·2023-09-12
CVE-2023-40611 [MEDIUM] Apache Airflow Incorrect Authorization vulnerability
Apache Airflow Incorrect Authorization vulnerability
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.
Users should upgrade to version 2.7.1 or later which has removed the vulnerability.
No detection rules found.
No public exploits indexed.
HackerOne
CVE-2023-47037: Airflow Broken Access Control Vulnerability
hackerone·2023-11-29·CVSS 4.3
CVE-2023-47037 [MEDIUM] CVE-2023-47037: Airflow Broken Access Control Vulnerability
CVE-2023-47037: Airflow Broken Access Control Vulnerability
Hi IBB,
Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.
Here is the conversation between the security team of airflow.
█████
More Details:
https://lists.apache.org/thread/04y4vrw1t2xl030gswtctc4nt1w90cb0
## Impact
Broken Access Control Vulnerability.
CVE-2023-47037: Apache Airflow missing fix for CVE-2023-40611 in 2.7.1 (DAG run broken access)
Severity: low
Affected versions:
- Apache Airflow before 2.7.3
Description:
We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixe
HackerOne
CVE-2023-40611: Apache Airflow Dag Runs Broken Access Control Vulnerability
hackerone·2023-10-27·CVSS 4.3
CVE-2023-40611 [MEDIUM] CVE-2023-40611: Apache Airflow Dag Runs Broken Access Control Vulnerability
CVE-2023-40611: Apache Airflow Dag Runs Broken Access Control Vulnerability
##Description:
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.
Users should upgrade to version 2.7.1 or later which has removed the vulnerability.
##Vulnerability Exploitation:
1.Select Browse-->DAG Runs, we can see the Dag Run list.
{F2691945}
2.Select a Dag, and edit it.
{F2691944}
3. We can see that the Conf parameter text box is gray and cannot be edited. The current user does not have permission to modify the Conf value.
{F2691946}
4.Click Save to intercept the request message an
http://www.openwall.com/lists/oss-security/2023/11/12/1https://github.com/apache/airflow/pull/33413https://lists.apache.org/thread/8y9xk1s3j4qr36yzqn8ogbn9fl7pxrn0http://www.openwall.com/lists/oss-security/2023/11/12/1https://github.com/apache/airflow/pull/33413https://lists.apache.org/thread/8y9xk1s3j4qr36yzqn8ogbn9fl7pxrn0
2023-09-12
Published