Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access.  Users of Apache Airflow are recommended to upgrade to version 2.8.3 or newer to mitigate the risk associated with this vulnerability
History

Wed, 11 Dec 2024 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache airflow
CPEs cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache airflow
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2024-03-14T08:41:03.928Z

Updated: 2024-08-02T00:56:58.123Z

Reserved: 2024-03-08T08:28:25.706Z

Link: CVE-2024-28746

cve-icon Vulnrichment

Updated: 2024-05-23T19:01:17.939Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-14T09:15:47.577

Modified: 2024-12-11T15:42:56.887

Link: CVE-2024-28746

cve-icon Redhat

No data.