Apache

Airflow

162 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.65%
  • Veröffentlicht 01.06.2026 09:16:18
  • Zuletzt bearbeitet 21.07.2026 19:10:00

A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe_url` check, enabling redirection from a trusted Airflow domain to an attacker-controlled origin. Users are advised to upgrade to ...

  • EPSS 0.48%
  • Veröffentlicht 01.06.2026 09:16:18
  • Zuletzt bearbeitet 21.07.2026 19:10:00

The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking whether the caller had read permission on those linked Dags. An authenticated UI/API user authorized for one Dag could enumerate l...

  • EPSS 0.37%
  • Veröffentlicht 01.06.2026 09:16:18
  • Zuletzt bearbeitet 21.07.2026 19:10:00

The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization. An authenticated UI/API user with global Asset:read permission could enumerate partition run state, schedule configuration, and ...

  • EPSS 0.35%
  • Veröffentlicht 01.06.2026 09:16:18
  • Zuletzt bearbeitet 21.07.2026 19:10:00

Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Airflow API server behind an HTTPS-terminating reverse proxy (e.g. nginx / Envoy / a managed load balancer that terminates TLS and f...

  • EPSS 0.48%
  • Veröffentlicht 01.06.2026 09:16:18
  • Zuletzt bearbeitet 21.07.2026 19:10:00

A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstances`) evaluated authorization against the `dag_id` resolved from the URL path while operating on the `dag_id` / `dag_run_id` extract...

  • EPSS 0.38%
  • Veröffentlicht 01.06.2026 09:16:18
  • Zuletzt bearbeitet 21.07.2026 19:10:00

Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(bash_command="echo value: {{ dag_run.conf['conf1'] }}")` example without any quoting / sanitization wa...

  • EPSS 0.35%
  • Veröffentlicht 01.06.2026 09:16:18
  • Zuletzt bearbeitet 21.07.2026 19:10:00

A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `secret`, `api_key`) to be bypassed when the JSON value's nesting depth exceeded the shared secrets maske...

  • EPSS 0.57%
  • Veröffentlicht 01.06.2026 09:16:18
  • Zuletzt bearbeitet 21.07.2026 19:10:00

A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on a Dag to set XCom entries under reserved key names (e.g. `return_value`) that the matching POST endpoin...

  • EPSS 0.69%
  • Veröffentlicht 01.06.2026 09:16:17
  • Zuletzt bearbeitet 21.07.2026 19:10:00

A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable by the API server process (read-path attack — e.g. `/etc/passwd` or `airflow.cfg`) or (b) supply a `task_id` containing `..` sequen...

  • EPSS 0.43%
  • Veröffentlicht 01.06.2026 06:51:41
  • Zuletzt bearbeitet 21.07.2026 18:10:00

A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read permission to retrieve secrets stored in a Connection's `extra` JSON blob under field names not prese...