Loading HuntDB...

GHSA-269x-pg5c-5xgm

GitHub Security Advisory

Apache Airflow Execution with Unnecessary Privileges

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Airflow.The "Run Task" feature enables authenticated user to bypass some of the restrictions put in place. It allows to execute code in the webserver context as well as allows to bypas limitation of access the user has to certain DAGs. The "Run Task" feature is considered dangerous and it has been removed entirely in Airflow 2.6.0.

This issue affects Apache Airflow: before 2.6.0.

Affected Packages

PyPI apache-airflow
Affected versions: 0 (fixed in 2.6.0b1)

Related CVEs

Key Information

GHSA ID
GHSA-269x-pg5c-5xgm
Published
August 5, 2023 9:30 AM
Last Modified
February 13, 2025 7:10 PM
CVSS Score
7.5 /10
Primary Ecosystem
PyPI
Primary Package
apache-airflow
GitHub Reviewed
✓ Yes

Dataset

Last updated: November 24, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.