Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-38540

The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution. This issue affects Apache Airflow >=2.0.0, <2.1.3.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.9
EPSS Ranking 99.6%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2021-38540
  • Apache » Airflow » Version: 2.0.0
    cpe:2.3:a:apache:airflow:2.0.0
  • Apache » Airflow » Version: 2.0.1
    cpe:2.3:a:apache:airflow:2.0.1
  • Apache » Airflow » Version: 2.0.2
    cpe:2.3:a:apache:airflow:2.0.2
  • Apache » Airflow » Version: 2.1.0
    cpe:2.3:a:apache:airflow:2.1.0
  • Apache » Airflow » Version: 2.1.1
    cpe:2.3:a:apache:airflow:2.1.1
  • Apache » Airflow » Version: 2.1.2
    cpe:2.3:a:apache:airflow:2.1.2


Contact Us

Shodan ® - All rights reserved