CVE-2022-38170
02.09.2022, 07:15
In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local users to expose arbitrary file contents via the webserver.Enginsight
Vendor | Product | Version |
---|---|---|
apache | airflow | 𝑥 < 2.3.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References