CVE-2023-25754: Apache Airflow: Privilege escalation using airflow logs
Published May 8, 2023
·Updated
Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow. This issue affects Apache Airflow: before 2.6.0.
Other sources
Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0.
Affected Software
2 affected componentsFixes available
Apache Airflow<2.6.0
pip/apache-airflow<2.6.0b1
2.6.0b1
Remediation
Patch Available
Event History
May 8, 2023
CVE Published
via MITRE·11:57 AM
Data Sourced
via MITRE·11:57 AM
DescriptionWeakness
Data Sourced
12:15 PM
DescriptionWeakness
Advisory Published
via GitHub·12:30 PM
Frequently Asked Questions
1
What is CVE-2023-25754?
CVE-2023-25754 is a Privilege Context Switching Error vulnerability in Apache Airflow.
2
Which version of Apache Airflow is affected by CVE-2023-25754?
Apache Airflow versions before 2.6.0 are affected by CVE-2023-25754.
3
What is the severity of CVE-2023-25754?
CVE-2023-25754 has a severity rating of 9.8 (Critical).
4
How can I mitigate the CVE-2023-25754 vulnerability?
To mitigate the CVE-2023-25754 vulnerability, update Apache Airflow to version 2.6.0 or higher.
5
Where can I find more information about CVE-2023-25754?
You can find more information about CVE-2023-25754 in the references provided: [link1], [link2], [link3].