Loading HuntDB...

GHSA-5938-79hg-xh3q

GitHub Security Advisory

Apache Airflow Improper Access Control vulnerability

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable.
This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification.
Users are recommended to upgrade to 2.8.0, which fixes this issue.

Affected Packages

PyPI apache-airflow
Affected versions: 0 (fixed in 2.8.0)

Related CVEs

Key Information

GHSA ID
GHSA-5938-79hg-xh3q
Published
December 21, 2023 12:30 PM
Last Modified
November 21, 2024 9:36 PM
CVSS Score
5.0 /10
Primary Ecosystem
PyPI
Primary Package
apache-airflow
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.