CVE-2026-24098
Apache Airflow: Assigning single DAG permission leaked all DAGs Import Errors
6.5
MEDIUM
CVSS 3.1
EPSS 0.74%
描述
Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later, which resolves this issue
如何修補 CVE-2026-24098
要修補 CVE-2026-24098,請將受影響套件升級到下列已修補版本。
- —升級至 3.1.7 或更新版本
- —升級至 3.1.7 或更新版本
- —升級至 3.1.7 或更新版本
CVE-2026-24098 正在被利用嗎?
低 — EPSS 為 0.7%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 3.1.7
- from 0, < 3.1.7
- >= 3.0.0, < 3.1.7
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |