Rewterz
Rewterz Threat Advisory – CVE-2023-41835 – Apache Struts Vulnerability
September 14, 2023
Rewterz
Rewterz Threat Alert – RedLine Stealer – Active IOCs
September 14, 2023

Rewterz Threat Advisory – Multiple Apache Airflow Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2023-40712 CVSS:6.5

Apache Airflow could allow a remote authenticated attacker to obtain sensitive information, caused by improper information protection in the UI. By sending a specially crafted request, an attacker could exploit this vulnerability to view secret configuration of the task, and use this information to launch further attacks against the affected system.

CVE-2023-40611 CVSS:4.3

Apache Airflow could allow a remote authenticated attacker to bypass security restrictions, caused by improper authorization validation. By sending a specially-crafted request, an attacker could exploit this vulnerability to modify some DAG run detail values.

Impact

  • Information Disclosure
  • Security Bypass

Indicators Of Compromise

CVE

  • CVE-2023-40712
  • CVE-2023-40611

Affected Vendors

Apache

Affected Products

  • Apache Airflow 2.7.0

Remediation

Upgrade to the latest version of Apache Airflow, available from the Apache Website.

Apache Website