CVE-2021-45230: Apache Airflow: Creating DagRuns didn't respect Dag-level permissions in the Webserver
In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "cancreate" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-45230?
CVE-2021-45230 is a vulnerability in Apache Airflow prior to version 2.2.0 that allows users with 'can_create' permissions to create Dag Runs for dags they don't have 'edit' permissions for.
How does CVE-2021-45230 affect Apache Airflow?
CVE-2021-45230 affects Apache Airflow versions prior to 2.2.0.
What is the severity of CVE-2021-45230?
The severity of CVE-2021-45230 is medium, with a severity value of 6.5.
How can I fix CVE-2021-45230?
To fix CVE-2021-45230, upgrade Apache Airflow to version 2.2.0 or later.
Where can I find more information about CVE-2021-45230?
More information about CVE-2021-45230 can be found at the following reference: [CVE-2021-45230](https://lists.apache.org/thread/m778ojn0k595rwco4ht9wjql89mjoxnl)