← volver
CVE-2021-26559

CWE-284 Improper Access Control on Configurations Endpoint for the Stable API

EPSS 2.8%CWE-284
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS EPSS 2.8%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
17 feb 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow.cfg`. This allowed a privilege escalation attack. This issue affects Apache Airflow 2.0.0.

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →