Description
In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local users to expose arbitrary file contents via the webserver.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Workaround
Run without the `--daemon` flag via a process supervisor instead (systemd, runit, etc.).
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0008 | In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local users to expose arbitrary file contents via the webserver. |
Github GHSA |
GHSA-q8h9-pqcx-59hw | Apache Airflow exposes arbitrary file content |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-03T10:45:52.810Z
Reserved: 2022-08-11T00:00:00.000Z
Link: CVE-2022-38170
No data.
Status : Modified
Published: 2022-09-02T07:15:07.833
Modified: 2024-11-21T07:15:55.980
Link: CVE-2022-38170
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA