漏洞标题
Apache Airflow:实验性API的线程归属API端点缺少身份验证检查
漏洞描述信息
Apache Airflow:实验性API的 lineage API端点缺少身份验证检查
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
漏洞类别
N/A
漏洞标题
Apache Airflow: Lineage API endpoint for Experimental API missed authentication check
漏洞描述信息
The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to hit that endpoint. This is low-severity issue as the attacker needs to be aware of certain parameters to pass to that endpoint and even after can just get some metadata about a DAG and a Task. This issue affects Apache Airflow 2.0.0.
CVSS信息
N/A
漏洞类别
特权管理不恰当
漏洞标题
Apache Airflow 访问控制错误漏洞
漏洞描述信息
Apache Airflow是美国阿帕奇(Apache)基金会的一套用于创建、管理和监控工作流程的开源平台。该平台具有可扩展和动态监控等特点。 Apache Airflow 2.0.0 存在访问控制错误漏洞,该漏洞源于已弃用的实验性API的沿袭端点没有受到身份验证的保护。
CVSS信息
N/A
漏洞类别
授权问题