Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access.  Users of Apache Airflow are recommended to upgrade to version 2.8.3 or newer to mitigate the risk associated with this vulnerability
CVSS

No CVSS.

History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: apache

Published: 2024-03-14T08:41:03.928Z

Updated: 2024-06-04T18:03:56.047Z

Reserved: 2024-03-08T08:28:25.706Z


Link: CVE-2024-28746

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-03-14T09:15:47.577

Modified: 2024-05-01T19:15:22.510


Link: CVE-2024-28746

JSON object: View

cve-icon Redhat Information

No data.

CWE