Loading HuntDB...

CVE-2021-38540

UNKNOWN
Published 2021-09-09T15:05:09
Actions:
No CVSS data available

Description

The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution. This issue affects Apache Airflow >=2.0.0, <2.1.3.

Available Exploits

Apache Airflow - Unauthenticated Variable Import

Apache Airflow Airflow >=2.0.0 and <2.1.3 does not protect the variable import endpoint which allows unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution.

ID: CVE-2021-38540
Author: pdteam Critical

Related News

No news articles found for this CVE.

Affected Products

References

Published: 2021-09-09T15:05:09
Last Modified: 2024-08-04T01:44:23.448Z
Copied to clipboard!