CVE Published: 09/09/2021 |
CVE Updated: 04/08/2024 |
CVE Year: 2021 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache Airflow Status : PUBLISHED
CVE-2021-38540 Description
The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution. This issue affects Apache Airflow >=2.0.0, <2.1.3.