CVE-2023-47037
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2023-47037. We'll provide specific mitigation strategies based on your environment and risk profile.
Description
We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.
Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.
Users should upgrade to version 2.7.3 or later which has removed the vulnerability.
Available Exploits
Related News
Affected Products
Affected Versions:
GitHub Security Advisories
Community-driven vulnerability intelligence from GitHub
Apache Airflow allows authenticated and DAG-view authorized users to modify some DAG run detail values when submitting notes
GHSA-hm9r-7f84-25c9Advisory Details
Affected Packages
CVSS Scoring
CVSS Score
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
References
Advisory provided by GitHub Security Advisory Database. Published: November 12, 2023, Modified: February 13, 2025