CVE-2023-40611

CVE-2023-40611: Apache Airflow Dag Runs Broken Access Control Vulnerability

Vendor Apache Software Foundation
Product Apache Airflow
Weakness CWE-863 · Incorrect authorization
Published September 12, 2023
Last update June 25, 2025

CVSS base score

What the vulnerability does

Description

Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc. Users should upgrade to version 2.7.1 or later which has removed the vulnerability.

Key dates

Disclosure timeline

September 12, 2023 CVE published
June 25, 2025 Record updated