CVE-2023-49920

Severity
6.5MEDIUM
EPSS
0.2%
top 60.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 21
Latest updateJan 9

Description

Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. As a result, it was possible for a malicious website opened in the same browser - by the user who also had Airflow UI opened - to trigger the execution of DAGs without the user's consent. Users are advised to upgrade to version 2.8.0 or later which is not affected

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

PyPIapache-airflow2.7.02.8.0+1
NVDapache/airflow2.7.02.7.3

Patches

🔴Vulnerability Details

4
CVEList
Apache Airflow: Missing CSRF protection on DAG/trigger2023-12-21
GHSA
Apache Airflow Cross-Site Request Forgery vulnerability2023-12-21
OSV
CVE-2023-49920: Apache Airflow, version 22023-12-21
OSV
Apache Airflow Cross-Site Request Forgery vulnerability2023-12-21

💬Community

1
HackerOne
CVE-2023-49920: Apache Airflow: Missing CSRF protection on DAG/trigger2024-01-09
CVE-2023-49920 (MEDIUM CVSS 6.5) | Apache Airflow | cvebase.io