CVE-2023-35908: Apache Airflow: Access to DAGs without relevant permission
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommended to upgrade to a version that is not affected
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/apache-airflowto a version that resolves this vulnerability.Fixed in 2.6.3 - Upgrade
Upgrade
apache/airflowto a version that resolves this vulnerability.Fixed in 2.6.3
Event History
Frequently Asked Questions
What is the vulnerability ID for this Apache Airflow vulnerability?
The vulnerability ID for this Apache Airflow vulnerability is CVE-2023-35908.
What is the severity of CVE-2023-35908?
The severity of CVE-2023-35908 is medium with a severity value of 6.5.
How does CVE-2023-35908 affect Apache Airflow?
CVE-2023-35908 allows unauthorized read access to a DAG through the URL in Apache Airflow versions before 2.6.3.
How can I fix CVE-2023-35908 in Apache Airflow?
To fix CVE-2023-35908 in Apache Airflow, it is recommended to upgrade to a version that is not affected, specifically version 2.6.3 or higher.
Where can I find more information about CVE-2023-35908?
More information about CVE-2023-35908 can be found at the following references: [GitHub Pull Request](https://github.com/apache/airflow/pull/32014), [Apache Mailing List](https://lists.apache.org/thread/vsflptk5dt30vrfggn96nx87d7zr6yvw), and [NVD CVE Details](https://nvd.nist.gov/vuln/detail/CVE-2023-35908).