oss-sec mailing list archives
CVE-2025-62503: Apache Airflow: Privilege boundary bypass in bulk APIs (create action can upsert existing Pools/Connections/Variables)
From: Kaxil Naik <kaxilnaik () gmail com>
Date: Wed, 29 Oct 2025 20:17:42 +0000
Severity: low Affected versions: - Apache Airflow (apache-airflow> 3.0.0, < 3.1.1) 3.0.0 before 3.1.1 Description: User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action. Credit: Maciej Kawka (finder) References: https://lists.apache.org/thread/3v58249qscyn1hg240gh8hqg9pb4okcr https://airflow.apache.org/ https://www.cve.org/CVERecord?id=CVE-2025-62503
Current thread:
- CVE-2025-62503: Apache Airflow: Privilege boundary bypass in bulk APIs (create action can upsert existing Pools/Connections/Variables) Kaxil Naik (Oct 29)
