CVE-2023-47037
published 2023-11-12CVE-2023-47037: We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then. Apache Airflow, versions before 2.7.3, is affected by a…
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
1.50%
71.2th percentile
We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.
Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.
Users should upgrade to version 2.7.3 or later which has removed the vulnerability.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | < 2.7.3 | 2.7.3 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
osv4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Airflow allows authenticated and DAG-view authorized users to modify some DAG run detail values when submitting notes
osv·2023-11-12
CVE-2023-47037 [MEDIUM] Apache Airflow allows authenticated and DAG-view authorized users to modify some DAG run detail values when submitting notes
Apache Airflow allows authenticated and DAG-view authorized users to modify some DAG run detail values when submitting notes
Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc. Users should upgrade to version 2.7.3 or later which has removed the vulnerability.
GHSA
Apache Airflow allows authenticated and DAG-view authorized users to modify some DAG run detail values when submitting notes
ghsa·2023-11-12
CVE-2023-47037 [MEDIUM] CWE-285 Apache Airflow allows authenticated and DAG-view authorized users to modify some DAG run detail values when submitting notes
Apache Airflow allows authenticated and DAG-view authorized users to modify some DAG run detail values when submitting notes
Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc. Users should upgrade to version 2.7.3 or later which has removed the vulnerability.
OSV
CVE-2023-47037: We failed to apply CVE-2023-40611 in 2
osv·2023-11-12·CVSS 4.3
CVE-2023-47037 [MEDIUM] CVE-2023-47037: We failed to apply CVE-2023-40611 in 2
We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.
Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.
Users should upgrade to version 2.7.3 or later which has removed the vulnerability.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2023/11/12/1https://github.com/apache/airflow/pull/33413https://lists.apache.org/thread/04y4vrw1t2xl030gswtctc4nt1w90cb0http://www.openwall.com/lists/oss-security/2023/11/12/1https://github.com/apache/airflow/pull/33413https://lists.apache.org/thread/04y4vrw1t2xl030gswtctc4nt1w90cb0
2023-11-12
Published