Loading HuntDB...

GHSA-j3w8-2p2h-mrr9

GitHub Security Advisory

Apache Airflow vulnerable to privilege escalation

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could give the user write access to various DAG resources for DAGs that the user had no access to, thus, enabling the user to clear DAGs they shouldn't.

Users of Apache Airflow are strongly advised to upgrade to version 2.7.2 or newer to mitigate the risk associated with this vulnerability.

Affected Packages

PyPI apache-airflow
Affected versions: 0 (fixed in 2.7.2)

Related CVEs

Key Information

GHSA ID
GHSA-j3w8-2p2h-mrr9
Published
October 14, 2023 12:30 PM
Last Modified
February 13, 2025 7:18 PM
CVSS Score
5.0 /10
Primary Ecosystem
PyPI
Primary Package
apache-airflow
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.