Junglewise Threat Intelligence

CVE-2020-13927: PYSEC-2020-18 - The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security ri

CVE-2020-13927 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2020-11-10

Technologies: apache-airflow (PyPI), Apache Airflow. Vendors: Apache, PyPI.

Executive brief

Apache Airflow's Experimental API was configured by default to allow all requests without authentication. This insecure default initialization allows unauthenticated remote attackers to perform critical functions, potentially leading to remote code execution.

Affected products

  • Apache Airflow versions up to 1.10.10

Timeline

  • 2020-11-24: disclosed: Initial analysis by NIST
  • 2022-01-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-01-18: advisory: NVD publication date

Related threats