CVE-2024-28746: Apache Airflow: Ignored Airflow Permissions
Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access.
Users of Apache Airflow are recommended to upgrade to version 2.8.3 or newer to mitigate the risk associated with this vulnerability
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28746?
CVE-2024-28746 is considered to have a medium severity rating due to its potential to compromise data access controls for authenticated users.
How do I fix CVE-2024-28746?
To fix CVE-2024-28746, upgrade Apache Airflow to version 2.8.3rc1 or later.
Who is affected by CVE-2024-28746?
CVE-2024-28746 affects users of Apache Airflow versions 2.8.0 through 2.8.2.
What types of data can be accessed due to CVE-2024-28746?
Due to CVE-2024-28746, users can access resources they do not have permission for, including variables and connections.
Is authentication required to exploit CVE-2024-28746?
Yes, CVE-2024-28746 requires an authenticated user to exploit the vulnerability.