CVE-2023-50783
published 2023-12-21CVE-2023-50783: Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a…
PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
1.39%
69.1th percentile
Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable.
This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification.
Users are recommended to upgrade to 2.8.0, which fixes this issue
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | < 2.8.0 | 2.8.0 |
| apache_software_foundation | apache_airflow | < 2.8.0 | 2.8.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-50783: Apache Airflow, versions before 2
osv·2023-12-21
CVE-2023-50783 CVE-2023-50783: Apache Airflow, versions before 2
Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable.
This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification.
Users are recommended to upgrade to 2.8.0, which fixes this issue
OSV
Apache Airflow Improper Access Control vulnerability
osv·2023-12-21
CVE-2023-50783 [MEDIUM] Apache Airflow Improper Access Control vulnerability
Apache Airflow Improper Access Control vulnerability
Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable.
This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification.
Users are recommended to upgrade to 2.8.0, which fixes this issue.
GHSA
Apache Airflow Improper Access Control vulnerability
ghsa·2023-12-21
CVE-2023-50783 [MEDIUM] CWE-284 Apache Airflow Improper Access Control vulnerability
Apache Airflow Improper Access Control vulnerability
Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable.
This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification.
Users are recommended to upgrade to 2.8.0, which fixes this issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2023/12/21/4https://github.com/apache/airflow/pull/33932https://lists.apache.org/thread/rs7cr3yp726mb89s1m844hy9pq7frgcnhttp://www.openwall.com/lists/oss-security/2023/12/21/4https://github.com/apache/airflow/pull/33932https://lists.apache.org/thread/rs7cr3yp726mb89s1m844hy9pq7frgcn
2023-12-21
Published