漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.target
Vulnerability Description
A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of trigger / sensor dependency entries. An authenticated UI user with read permission on some Dags could enumerate the identifiers of other Dags they were not authorized to read by inspecting the dependency graph for trigger / sensor references. Affects deployments that rely on per-Dag read scoping to keep Dag identifiers private across teams. This is a residual gap in the fix for CVE-2026-28563, which filtered the top-level Dag key but did not propagate the filter into the trigger / sensor dep-source / dep-target fields. Users who already upgraded for CVE-2026-28563 should additionally upgrade to `apache-airflow` 3.3.0 or later to cover the residual trigger / sensor dependency leak.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
Apache Airflow 信息泄露漏洞
Vulnerability Description
Apache Software Foundation Apache Airflow是Apache Software Foundation基金会的开源工作流调度与数据管道编排平台。 Apache Airflow 3.3.0之前版本存在信息泄露漏洞,该漏洞源于依赖调度图端点中对调用者可读Dag过滤器的应用不当,导致在触发/传感器依赖条目的dep.source和dep.target字段中泄露了未授权用户应ID标识符。未经授权的用户可利用此漏洞枚举其未授权读取的Dag标识符,从而引发信息泄露风险。以下版本受到影响
CVSS Information
N/A
Vulnerability Type
N/A