Back to search
CVE-2021-26559
Published: Feb 17, 2021
Modified: Feb 13, 2025
PUBLISHED
Description
Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow.cfg`. This allowed a privilege escalation attack. This issue affects Apache Airflow 2.0.0.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache Airflow | affected Apache Airflow 2.0.0 |
Weaknesses (CWE)
References
[announce] 20210217 CVE-2021-26559: Apache Airflow: CWE-284 Privilege Escalation Attack
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now