Apache Airflow
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*
- >= 3.0.0, < 3.1.1
A vulnerability exists in Apache Airflow versions 3.0.0 prior to 3.1.1, allowing users with CREATE privileges but no UPDATE privileges for Pools, Connections, or Variables to overwrite existing records. This is achieved through the bulk create API by using the overwrite action.
Exploitation of this vulnerability allows for unauthorized modification of existing Pools, Connections, or Variables, potentially leading to unintended changes in workflow management or execution.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.