Apache Airflow
0 remedies
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*
0 remedies
- >= 3.0.0, < 3.1.1
A vulnerability in Apache Airflow versions 3.0.0 prior to 3.1.1 allows API users to execute DAG code through the '/api/v2/dagReports' endpoint. This issue arises if the API server is deployed in an environment where DAG files are accessible.
Exploitation of this vulnerability could lead to unauthorized execution of DAG Python code in the context of the API server.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.