Vulnerability advisory

CVE-2023-47037

Research by Md. Tareq Ahamed Jony November 12, 2023
Overview

Summary

We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.  Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.  Users should upgrade to version 2.7.3 or later which has removed the vulnerability.

Risk profile

CVSS assessment

4.3 · M E D I U M
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack vector
N E T W O R K
Complexity
L O W
Privileges
L O W
User interaction
N O N E
Scope
U N C H A N G E D
Confidentiality
N O N E
Integrity
L O W
Availability
N O N E
Classification

Weaknesses

  • Incorrect Authorization CWE-863
Configurations

Affected products

1 configuration
Vulnerable match
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*
Before 2.7.3
Further reading

References

3 sources
  1. www.openwall.com http://www.openwall.com/lists/oss-security/2023/11/12/1 Mailing List Third Party Advisory
  2. github.com https://github.com/apache/airflow/pull/33413 Issue Tracking Patch
  3. lists.apache.org https://lists.apache.org/thread/04y4vrw1t2xl030gswtctc4nt1w90cb0 Mailing List