← volver
CVE-2023-50783

Apache Airflow: Improper access control vulnerability on the "varimport" endpoint

EPSS 1.4%CWE-284
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS EPSS 1.4%KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
21 dic 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable. This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification. Users are recommended to upgrade to 2.8.0, which fixes this issue

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →