Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when [webserver] expose_config
is set to False
in airflow.cfg
. This allowed a privilege escalation attack. This issue affects Apache Airflow 2.0.0.
{ "nvd_published_at": "2021-02-17T15:15:00Z", "cwe_ids": [ "CWE-269", "CWE-284" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-04-01T23:27:01Z" }