Apache

Airflow

162 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 29.09.2026 10:17:12
  • Zuletzt bearbeitet 07.10.2026 20:05:46

Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperator` and `AzureBlobStorageToTeradataOperator` interpolate the source bucket's credentials as plain string literals into the `CREATE ...

  • EPSS 0.4%
  • Veröffentlicht 21.09.2026 14:33:26
  • Zuletzt bearbeitet 25.09.2026 13:53:06

Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout response but ...

  • EPSS 0.23%
  • Veröffentlicht 21.09.2026 14:32:47
  • Zuletzt bearbeitet 25.09.2026 13:58:05

Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. Any authenticated user holding asset-read access could therefore enumerate asse...

  • EPSS 0.27%
  • Veröffentlicht 21.09.2026 14:32:04
  • Zuletzt bearbeitet 25.09.2026 19:43:35

When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer over cookie. The...

  • EPSS 0.17%
  • Veröffentlicht 18.09.2026 07:51:23
  • Zuletzt bearbeitet 22.09.2026 19:16:44

Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authenticated user who could read a Dag could therefore delete that Dag's queued asset events, silently suppressing asse...

  • EPSS 0.11%
  • Veröffentlicht 12.08.2026 15:43:17
  • Zuletzt bearbeitet 16.09.2026 15:17:39

Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `va...

  • EPSS 0.28%
  • Veröffentlicht 12.08.2026 15:40:59
  • Zuletzt bearbeitet 16.09.2026 15:17:38

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An o...

  • EPSS 0.25%
  • Veröffentlicht 12.08.2026 15:35:00
  • Zuletzt bearbeitet 16.09.2026 15:17:38

Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom wr...

  • EPSS 0.26%
  • Veröffentlicht 12.08.2026 15:34:22
  • Zuletzt bearbeitet 16.09.2026 15:17:37

Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an Airflow Varia...

  • EPSS 0.78%
  • Veröffentlicht 12.08.2026 15:33:02
  • Zuletzt bearbeitet 16.09.2026 15:17:40

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that va...