← voltar
CVE-2021-35936CWE-200

No Authentication on Logging Server

3Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackepss 5.5%
probabilidade de exploração
5.5%top 8% das CVEs
exploração observada
nãonenhuma fonte reporta
If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor) runs a Flask logging server and is listening on a specific port and also binds on 0.0.0.0 by default. This logging server had no authentication and allows reading log files of DAG jobs. This issue affects Apache Airflow < 2.1.2.