Apache Airflow
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*
- >= 3.1.0, <= 3.1.7
A vulnerability in Apache Airflow versions 3.1.0 prior to 3.1.8 allows an authenticated user with DAG Dependencies permission to bypass authorization. The /ui/dependencies endpoint exposes the complete DAG dependency graph without restricting access based on authorized DAG IDs. This flaw enables users to enumerate DAGs they are not permitted to view.
Exploitation of this vulnerability could lead to unauthorized visibility of DAGs, allowing users to access information they should not be able to see.
Users are advised to upgrade to Apache Airflow 3.1.8 or later, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.