CVE-2021-38540
Apache Airflow: Variable Import endpoint missed authentication check
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution. This issue affects Apache Airflow >=2.0.0, <2.1.3.
El endpoint de importación de variables no estaba protegido por autenticación en Airflow versiones posteriores a 2.0.0 incluyéndola, versiones anteriores a 2.1.3. Esto permitía a usuarios no autenticados acceder a ese endpoint para añadir y modificar las variables de Airflow usadas en los DAG, resultando en una denegación de servicio, una divulgación de información o una ejecución de código remota. Este problema afecta a Apache Airflow versiones posteriores a 2.0.0 incluyéndola, versiones anteriores a 2.1.3
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-08-11 CVE Reserved
- 2021-09-09 CVE Published
- 2022-06-13 First Exploit
- 2024-08-04 CVE Updated
- 2024-11-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-269: Improper Privilege Management
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://lists.apache.org/thread.html/rac2ed9118f64733e47b4f1e82ddc8c8020774698f13328ca742b03a2%40%3Cannounce.apache.org%3E | Mailing List |
URL | Date | SRC |
---|---|---|
https://github.com/Captain-v-hook/PoC-for-CVE-2021-38540- | 2022-06-13 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Airflow Search vendor "Apache" for product "Airflow" | >= 2.0.0 < 2.1.3 Search vendor "Apache" for product "Airflow" and version " >= 2.0.0 < 2.1.3" | - |
Affected
|