Lucene search

K
cvelistApacheCVELIST:CVE-2021-26697
HistoryFeb 17, 2021 - 2:15 p.m.

CVE-2021-26697 Apache Airflow: Lineage API endpoint for Experimental API missed authentication check

2021-02-1714:15:15
CWE-269
apache
www.cve.org

0.008 Low

EPSS

Percentile

81.1%

The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to hit that endpoint. This is low-severity issue as the attacker needs to be aware of certain parameters to pass to that endpoint and even after can just get some metadata about a DAG and a Task. This issue affects Apache Airflow 2.0.0.

CNA Affected

[
  {
    "product": "Apache Airflow",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "Apache Airflow 2.0.0"
      }
    ]
  }
]

0.008 Low

EPSS

Percentile

81.1%

Related for CVELIST:CVE-2021-26697