CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.3. It affects Apache. Exploitation may require the attacker to be authenticated.
CVE
CVE-2021-26697
Severity
MEDIUM
CVSS
5.3
EPSS
4.55%
Apache
Original NVD Description
The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to hit that endpoint. This is low-severity issue as the attacker needs to be aware of certain parameters to pass to that endpoint and even after can just get some metadata about a DAG and a Task. This issue affects Apache Airflow 2.0.0.
Related CVEs
Other vulnerabilities affecting the same vendor(s)