Executive brief
Apache Airflow is a workflow orchestration platform used to schedule and monitor data pipelines. The "Run Task" feature in the web interface allowed authenticated users to execute arbitrary code in the webserver's security context and bypass restrictions on accessing certain workflows, potentially exposing sensitive data or allowing unauthorized pipeline modifications. This feature has been removed in Airflow 2.6.0.
Technical details
The vulnerability is an improper privilege management issue (CWE-200) in Apache Airflow's "Run Task" feature. An authenticated user could invoke this feature to execute code with webserver privileges, bypassing access controls that normally restrict which directed acyclic graphs (DAGs) a user can interact with. The attack requires valid Airflow credentials but no special privileges. The "Run Task" functionality was completely removed in version 2.6.0b1 as the feature was fundamentally broken and dangerous. Organizations running Airflow prior to 2.6.0 should immediately upgrade or disable the Run Task feature.
Affected products
- Apache Airflow before 2.6.0
Timeline
- 2023-08-05: disclosed
- 2023-02-23: patched: Run Task feature removed in 2.6.0b1