apache-airflow-core is vulnerable to Incorrect Authorization
54
Medium Risk
Airflow's asset queued-events DELETE endpoints check the caller's permission on the Dag resource axis instead of the Asset resource axis the endpoint actually operates on. A caller with Dag-level permissions but no rights over the affected asset can still delete that asset's queued events. This lets queued-event data be deleted outside the authorization boundary the endpoint is supposed to enforce. The fix checks the caller's permission against the Asset resource axis.
You are affected if you are using a version that falls within the vulnerable range and use per resource authorization to restrict which users can manage a given asset's queued events.
apache-airflow-core is vulnerable to Incorrect Authorization in versions 0.0.1 - 3.3.1.
Upgrade the apache-airflow-core and/or the apache-airflow library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.