CVE-2024-28746: Apache Airflow: Ignored Airflow Permissions
Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access.
Users of Apache Airflow are recommended to upgrade to version 2.8.3 or newer to mitigate the risk associated with this vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/apache-airflowto a version that resolves this vulnerability.Fixed in 2.8.3rc1 - Upgrade
Upgrade
Apache Airflowto a version that resolves this vulnerability.Fixed in 2.8.3
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28746?
CVE-2024-28746 is considered to have a medium severity rating due to its potential to compromise data access controls for authenticated users.
How do I fix CVE-2024-28746?
To fix CVE-2024-28746, upgrade Apache Airflow to version 2.8.3rc1 or later.
Who is affected by CVE-2024-28746?
CVE-2024-28746 affects users of Apache Airflow versions 2.8.0 through 2.8.2.
What types of data can be accessed due to CVE-2024-28746?
Due to CVE-2024-28746, users can access resources they do not have permission for, including variables and connections.
Is authentication required to exploit CVE-2024-28746?
Yes, CVE-2024-28746 requires an authenticated user to exploit the vulnerability.