CVE-2023-49920
published 2023-12-21CVE-2023-49920: Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. As a…
PriorityP434medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
1.03%
59.8th percentile
Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. As a result, it was possible for a malicious website opened in the same browser - by the user who also had Airflow UI opened - to trigger the execution of DAGs without the user's consent.
Users are advised to upgrade to version 2.8.0 or later which is not affected
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | 2.7.0 – 2.7.3 | — |
| apache_software_foundation | apache_airflow | >= 2.7.0 < 2.8.0 | 2.8.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Airflow Cross-Site Request Forgery vulnerability
ghsa·2023-12-21
CVE-2023-49920 [MEDIUM] CWE-352 Apache Airflow Cross-Site Request Forgery vulnerability
Apache Airflow Cross-Site Request Forgery vulnerability
Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. As a result, it was possible for a malicious website opened in the same browser - by the user who also had Airflow UI opened - to trigger the execution of DAGs without the user's consent.
Users are advised to upgrade to version 2.8.0 or later which is not affected
OSV
CVE-2023-49920: Apache Airflow, version 2
osv·2023-12-21
CVE-2023-49920 CVE-2023-49920: Apache Airflow, version 2
Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. As a result, it was possible for a malicious website opened in the same browser - by the user who also had Airflow UI opened - to trigger the execution of DAGs without the user's consent.
Users are advised to upgrade to version 2.8.0 or later which is not affected
OSV
Apache Airflow Cross-Site Request Forgery vulnerability
osv·2023-12-21
CVE-2023-49920 [MEDIUM] Apache Airflow Cross-Site Request Forgery vulnerability
Apache Airflow Cross-Site Request Forgery vulnerability
Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. As a result, it was possible for a malicious website opened in the same browser - by the user who also had Airflow UI opened - to trigger the execution of DAGs without the user's consent.
Users are advised to upgrade to version 2.8.0 or later which is not affected
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2023/12/21/3https://github.com/apache/airflow/pull/36026https://lists.apache.org/thread/mnwd2vcfw3gms6ft6kl951vfbqrxsnjqhttp://www.openwall.com/lists/oss-security/2023/12/21/3https://github.com/apache/airflow/pull/36026https://lists.apache.org/thread/mnwd2vcfw3gms6ft6kl951vfbqrxsnjq
2023-12-21
Published