The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and is documented at https://airflow.apache.org/docs/1.10.11/security.html#api-authentication. Note this change fixes it for new installs but existing users need to change their config to default `[api]auth_backend = airflow.api.auth.backend.deny_all` as mentioned in the Updating Guide: https://github.com/apache/airflow/blob/1.10.11/UPDATING.md#experimental-api-will-deny-all-request-by-default
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/162908/Apache-Airflow-1.10.10-Remote-Code-Execution.html | Exploit Third Party Advisory VDB Entry |
http://packetstormsecurity.com/files/174764/Apache-Airflow-1.10.10-Remote-Code-Execution.html | Exploit Third Party Advisory VDB Entry |
https://lists.apache.org/thread.html/r23a81b247aa346ff193670be565b2b8ea4b17ddbc7a35fc099c1aadd%40%3Cdev.airflow.apache.org%3E | Mailing List Vendor Advisory |
Configurations
History
01 Aug 2024, 13:42
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-1056 |
14 Feb 2024, 17:16
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-306 | |
References | () http://packetstormsecurity.com/files/174764/Apache-Airflow-1.10.10-Remote-Code-Execution.html - Exploit, Third Party Advisory, VDB Entry | |
References | () https://lists.apache.org/thread.html/r23a81b247aa346ff193670be565b2b8ea4b17ddbc7a35fc099c1aadd%40%3Cdev.airflow.apache.org%3E - Mailing List, Vendor Advisory |
12 Jul 2022, 17:42
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-1188 |
01 Jan 2022, 18:18
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) http://packetstormsecurity.com/files/162908/Apache-Airflow-1.10.10-Remote-Code-Execution.html - Exploit, Third Party Advisory, VDB Entry |
02 Jun 2021, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2020-11-10 16:15
Updated : 2024-08-14 20:10
NVD link : CVE-2020-13927
Mitre link : CVE-2020-13927
CVE.ORG link : CVE-2020-13927
JSON object : View
Products Affected
apache
- airflow