CVE-2023-50783Improper Access Control in Software Foundation Apache Airflow

Severity
6.5MEDIUMNVD
EPSS
0.0%
top 87.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 21

Description

Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable. This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification. Users are recommended to upgrade to 2.8.0, which fixes this issue

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

4
OSV
CVE-2023-50783: Apache Airflow, versions before 22023-12-21
OSV
Apache Airflow Improper Access Control vulnerability2023-12-21
CVEList
Apache Airflow: Improper access control vulnerability on the "varimport" endpoint2023-12-21
GHSA
Apache Airflow Improper Access Control vulnerability2023-12-21
CVE-2023-50783 — Improper Access Control | cvebase