CVE-2020-13927 addresses a critical security flaw in Apache Airflow versions prior to 1.10.11, where the Experimental API defaulted to allowing unauthenticated access, posing significant risks. This vulnerability carries a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low complexity, and potential for complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, with readily available exploit code in Metasploit and Nuclei, and has garnered substantial community discussion and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.10.11CPE matchmatch criteria | cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.