Rewterz Threat Advisory – Multiple Dell PowerScale OneFS Vulnerabilities
November 14, 2023Rewterz Threat Alert – Royal Ransomware Demands $275 Million From 350 Victims – Active IOCs
November 14, 2023Rewterz Threat Advisory – Multiple Dell PowerScale OneFS Vulnerabilities
November 14, 2023Rewterz Threat Alert – Royal Ransomware Demands $275 Million From 350 Victims – Active IOCs
November 14, 2023Severity
Medium
Analysis Summary
CVE-2023-42781 CVSS:6.5
Apache Airflow could allow a remote authenticated attacker to obtain sensitive information, caused by a permission verification bypass flaw. By sending a specially crafted request, an attacker could exploit this vulnerability to read information about task instances in other DAGs, and use this information to launch further attacks against the affected system.
CVE-2023-47037 CVSS:6.5
Apache Airflow could allow a remote authenticated attacker to bypass security restrictions, caused by improper access control. By submitting specially crafted notes, an attacker could exploit this vulnerability to modify some DAG run detail values.
Impact
- Information Disclosure
- Security Bypass
Indicators Of Compromise
CVE
- CVE-2023-42781
- CVE-2023-47037
Affected Vendors
Apache
Affected Products
- Apache Airflow 2.7.2
Remediation
Upgrade to the latest version of Apache Airflow, available from the Apache Website.