apache-airflow is vulnerable to Authorization Bypass
35
Low Risk
The GET /api/v2/dagSources/{dag_id} endpoint and the equivalent UI view return the entire source file for a Dag. The response is not redacted for other Dags co-located in the same file, bypassing per-Dag read authorization. A user authorized to read one Dag can read the source of unrelated Dags that share the file. The fix redacts source when the caller lacks read access to every Dag in the file.
You are affected if you are using a version that falls within the vulnerable range and you co-locate multiple Dags in a single source file and rely on per-Dag read access control.
apache-airflow is vulnerable to Authorization Bypass in versions 3.0.0 - 3.2.2.
Upgrade the apache-airflow library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant