CVE-2020-13927

9.8CRITICAL

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the de

게시됨: 11/10/2020업데이트됨: 10/23/2025

CISA 알려진 악용 취약점

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.

필요한 조치:

Apply updates per vendor instructions.

마감일:

2022-07-18

설명

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and is documented at https://airflow.apache.org/docs/1.10.11/security.html#api-authentication. Note this change fixes it for new installs but existing users need to change their config to default `[api]auth_backend = airflow.api.auth.backend.deny_all` as mentioned in the Updating Guide: https://github.com/apache/airflow/blob/1.10.11/UPDATING.md#experimental-api-will-deny-all-request-by-default

AI 분석AI 기반

영향받는 제품

apacheairflow

사용 가능한 익스플로잇 (1)

참조