BIT-airflow-2021-26697

Import Source
https://github.com/bitnami/vulndb/tree/main/data/airflow/BIT-airflow-2021-26697.json
Aliases
Published
2024-03-06T10:59:36.299Z
Modified
2024-03-06T11:25:28.861Z
Details

The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to hit that endpoint. This is low-severity issue as the attacker needs to be aware of certain parameters to pass to that endpoint and even after can just get some metadata about a DAG and a Task. This issue affects Apache Airflow 2.0.0.

References

Affected packages

Bitnami / airflow

Package

Name
airflow

Affected ranges

Type
SEMVER
Events
Introduced
2.0.0
Last affected
2.0.0