Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <CAH5JyZp6v8xv3LvOGG0VG5tc7FAexPEu3cULqKv8Bjnk_Fc+=w@mail.gmail.com>
Date: Wed, 29 Oct 2025 20:17:42 +0000
From: Kaxil Naik <kaxilnaik@...il.com>
To: oss-security@...ts.openwall.com
Cc: users@...flow.apache.org, dev@...flow.apache.org
Subject: CVE-2025-62503: Apache Airflow: Privilege boundary bypass in bulk
 APIs (create action can upsert existing Pools/Connections/Variables)

Severity: low

Affected versions:

- Apache Airflow (apache-airflow> 3.0.0, < 3.1.1) 3.0.0 before 3.1.1

Description:

User with CREATE and no UPDATE privilege for Pools, Connections,
Variables could update existing records via bulk create API with
overwrite action.

Credit:

Maciej Kawka (finder)

References:

https://lists.apache.org/thread/3v58249qscyn1hg240gh8hqg9pb4okcr
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2025-62503

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.