Skip to content

CVE-2023-36543 | Apache Airflow

Apache Airflow, versions before 2.6.3, has a vulnerability where an authenticated user can use crafted input to make the current request hang. It is recommended to upgrade to a version that is not affected.This CVE has a CVSS3.1 score of 7.8 and a Base Severity of HIGH.

InfoDetails
CVE IDCVE-2023-36543
CVE StatePUBLISHED
BaseScoreNA
BaseSeverityNA
VectorStringNA
VersionNA

References for CVE-2023-36543 :
https://github.com/apache/airflow/pull/32060
https://lists.apache.org/thread/tokfs980504ylgk3cv3hjlnrtbv4tng4

Metric TypeMetric Score
AttackVector(AV)NA
AttackComplexity(AC)NA
PrivilegesRequired(PR)NA
UserInteraction(UI)NA
Scope(S)NA
Confidentiality(C)NA
Availability(A)NA
Integrity(I)NA