|
|
Message-ID: <CAH5JyZp6v8xv3LvOGG0VG5tc7FAexPEu3cULqKv8Bjnk_Fc+=w@mail.gmail.com> Date: Wed, 29 Oct 2025 20:17:42 +0000 From: Kaxil Naik <kaxilnaik@...il.com> To: oss-security@...ts.openwall.com Cc: users@...flow.apache.org, dev@...flow.apache.org Subject: CVE-2025-62503: Apache Airflow: Privilege boundary bypass in bulk APIs (create action can upsert existing Pools/Connections/Variables) Severity: low Affected versions: - Apache Airflow (apache-airflow> 3.0.0, < 3.1.1) 3.0.0 before 3.1.1 Description: User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action. Credit: Maciej Kawka (finder) References: https://lists.apache.org/thread/3v58249qscyn1hg240gh8hqg9pb4okcr https://airflow.apache.org/ https://www.cve.org/CVERecord?id=CVE-2025-62503
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.