CVE-2021-38540: Apache Airflow – Unauthenticated Variable Import

CVE-2021-38540: Apache Airflow - Unauthenticated Variable Import-渗透云记 - 专注于网络安全与技术分享
CVE-2021-38540: Apache Airflow – Unauthenticated Variable Import
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2021-38540: Apache Airflow – Unauthenticated Variable Import

漏洞描述

Apache Airflow Airflow >=2.0.0 and <2.1.3 does not protect the variable import endpoint which allows unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享