Description
Apache Airflow is an open-source workflow management platform for data engineering pipelines.
Acunetix determined that it was possible to access Airflow Experimental API without authentication(CVE-2020-13927).
Airflow is designed to be accessed by trusted clients inside trusted environments. It's not recommended to have it publicly accessible.
Remediation
Upgrade to the latest version of Airflow
References
Related Vulnerabilities
WordPress Plugin Simple Download Monitor Multiple Vulnerabilities (3.9.5.1)
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-28566)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-6455)
MyBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9410)
GraphQL Array-based Query Batching Allowed: Potential Batching Attack Vulnerability