CVE-2023-39508
Apache Airflow: Airflow "Run task" feature allows execution with unnecessary priviledges
8.8
HIGH
CVSS 3.1
EPSS 2.4%
描述
Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Airflow.The "Run Task" feature enables authenticated user to bypass some of the restrictions put in place. It allows to execute code in the webserver context as well as allows to bypas limitation of access the user has to certain DAGs. The "Run Task" feature is considered dangerous and it has been removed entirely in Airflow 2.6.0 This issue affects Apache Airflow: before 2.6.0.
如何修補 CVE-2023-39508
要修補 CVE-2023-39508,請將受影響套件升級到下列已修補版本。
- —升級至 2.6.0 或更新版本
- —升級至 2.6.0b1 或更新版本
- —升級至 2.6.0 或更新版本
CVE-2023-39508 正在被利用嗎?
低 — EPSS 為 2.4%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 2.6.0
- from 0, < 2.6.0b1
- from 0, < 2.6.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |