We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.  Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.  Users should upgrade to version 2.7.3 or later which has removed the vulnerability.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: apache

Published: 2023-11-12T13:12:23.137Z

Updated: 2023-11-12T13:12:23.137Z

Reserved: 2023-10-30T10:10:48.025Z


Link: CVE-2023-47037

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-12T14:15:25.980

Modified: 2023-11-20T19:31:24.707


Link: CVE-2023-47037

JSON object: View

cve-icon Redhat Information

No data.

CWE