apache-airflow is vulnerable to Authorization Bypass
62
Medium Risk
The asset materialization endpoint and the XCom result check on wait_dag_run_until_finished authorize the target Dag without its team, unlike other authorization sites. A team-aware auth manager therefore never consults the team-scoped permission that should gate the request. In multi-team mode an authenticated user in one team can trigger another team's Dag runs with their own configuration and read another team's XCom values. The fix resolves the Dag's team at both sites.
You are affected if you are using a version that falls within the vulnerable range and you run multi-team mode with a team-aware auth manager.
apache-airflow is vulnerable to Authorization Bypass in versions 3.2.0 - 3.3.0.
Upgrade the apache-airflow library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant