← back
CVE-2023-50783

Apache Airflow: Improper access control vulnerability on the "varimport" endpoint

EPSS 1.4%CWE-284
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 1.4%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
21 Dec 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable. This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification. Users are recommended to upgrade to 2.8.0, which fixes this issue

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →