Loading HuntDB...

GHSA-h574-6646-vfxx

GitHub Security Advisory

Apache Airflow: Ignored Airflow Permission

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access. 

Users of Apache Airflow are recommended to upgrade to version 2.8.3 or newer to mitigate the risk associated with this vulnerability

Affected Packages

PyPI apache-airflow
Affected versions: 2.8.0 (fixed in 2.8.3rc1)

Related CVEs

Key Information

GHSA ID
GHSA-h574-6646-vfxx
Published
March 14, 2024 9:31 AM
Last Modified
May 2, 2024 7:01 PM
CVSS Score
5.0 /10
Primary Ecosystem
PyPI
Primary Package
apache-airflow
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.