CVE-2024-27906
Last modified
CVE-2024-27906 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not have permission to view through the API and the UI. Users of Apache Airflow are recommended to upgrade to version 2.8.2 or newer to mitigate the risk associated with this vulnerability. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not have permission to view through the API and the UI. Users of Apache Airflow are recommended to upgrade to version 2.8.2 or newer to mitigate the risk associated with this vulnerability
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Airflow | < 2.8.2 |
References
- https://github.com/apache/airflow/pull/37290Broken Link
- https://github.com/apache/airflow/pull/37468Issue Tracking
- https://lists.apache.org/thread/on4f7t5sqr3vfgp1pvkck79wv7mq9st5Mailing List, Vendor Advisory
- https://github.com/apache/airflow/pull/37290Broken Link
- https://github.com/apache/airflow/pull/37468Issue Tracking
- https://lists.apache.org/thread/on4f7t5sqr3vfgp1pvkck79wv7mq9st5Mailing List, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-27906?
How severe is CVE-2024-27906?
How do I fix CVE-2024-27906?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-2790The HT Mega – Absolute Addons For Elementor plugin for WordP…5.4
- CVE-2024-27900Due to missing authorization check, attacker with business u…5.3
- CVE-2024-27901SAP Asset Accounting could allow a high privileged attacker …7.2
- CVE-2024-27902Applications based on SAP GUI for HTML in SAP NetWeaver AS A…6.1
- CVE-2024-27903OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier c…9.8
- CVE-2024-27905** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Inform…9.1
- CVE-2024-27907A vulnerability has been identified in Simcenter Femap (All …7.8
- CVE-2024-27908A buffer overflow vulnerability was reported in the HTTPS se…4.9
- CVE-2024-27909A denial of service vulnerability was reported in the HTTPS …4.9
- CVE-2024-2791The Metform Elementor Contact Form Builder plugin for WordPr…5.4
- CVE-2024-27910A vulnerability was reported in some Lenovo Printers that co…5.3
- CVE-2024-27911A vulnerability was reported in some Lenovo Printers that co…7.5
Are you affected by CVE-2024-27906?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
