CVE-2023-37379

HIGH

Apache Airflow < 2.7.0 - Authenticated Denial of Service via Connection Test Feature

Title source: llm
STIX 2.1

Description

Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection edit privileges. This vulnerability allows the user to access connection information and exploit the test connection feature by sending many requests, leading to a denial of service (DoS) condition on the server. Furthermore, malicious actors can leverage this vulnerability to establish harmful connections with the server. Users of Apache Airflow are strongly advised to upgrade to version 2.7.0 or newer to mitigate the risk associated with this vulnerability. Additionally, administrators are encouraged to review and adjust user permissions to restrict access to sensitive functionalities, reducing the attack surface.

References (3)

Core 3

Scores

CVSS v3 8.1
EPSS 0.0019
EPSS Percentile 40.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400 CWE-918 CWE-200
Status published
Products (2)
apache/airflow < 2.7.0
pypi/apache-airflow 0 - 2.7.0b1PyPI
Published Aug 23, 2023
Tracked Since Feb 18, 2026