Apache Airflow是美国Apache基金会开源的一个工作流调度和数据处理平台。 Apache Airflow 22.3.0之前版本存在权限许可和访问控制问题漏洞,该漏洞源于Google Cloud Secret Manager secrets backend未应用团队范围,导致team_name被丢弃,可能使一个团队的任务或DAG解析另一个团队的Connection或Variable,获取其完整凭据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Airflow Google provider | < 22.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Airflow Google provider | 0 ~ 22.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-68076 | Apache Airflow: Connections test API: team-scope guard bypass resolves another team's envi | |
| CVE-2026-68971 | Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run r | |
| CVE-2026-68970 | Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rende | |
| CVE-2026-68969 | Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit l | |
| CVE-2026-68968 | Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretatio | |
| CVE-2026-65017 | Apache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi- | |
| CVE-2026-67587 | Apache Airflow: DAG-author remote code execution on the Scheduler via a Serde `Callback` d | |
| CVE-2026-67260 | Apache Airflow: DAG-author remote code execution on the Scheduler via awaiting_input next_ | |
| CVE-2026-54183 | Apache Airflow: Airflow Variables were not masked in the UI for authenticated users | |
| CVE-2026-59242 | Apache Airflow: Arbitrary airflow.* class instantiation on the API server via the XCom des | |
| CVE-2026-58076 | Apache Airflow: Unguarded import_string() of airflow_exc_ser / base_exc_ser exception node | |
| CVE-2026-59244 | Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Temp | |
| CVE-2026-73240 | Apache Allura: Git command injection | |
| CVE-2026-73239 | Apache Allura: Missing permission checks IDOR | |
| CVE-2026-73238 | Apache Allura: XSS in code display | |
| CVE-2026-73237 | Apache Allura: XSS in markdown pipeline |
No comments yet