CVE-2020-13927
Apache Airflow's Experimental API Authentication Bypass
- 대응 우선순위
- 최우선
- CVSS
- 9.8
- EPSS
- 99.7% 백분위 100.0% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2022.07.18
- 공개일
- 2020.11.11
CISA KEV에 등록된 실제 악용 확인 취약점
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and is documented at https://airflow.apache.org/docs/1.10.11/security.html#api-authentication. Note this change fixes it for new installs but existing users need to change their config to default `[api]auth_backend = airflow.api.auth.backend.deny_all` as mentioned in the Updating Guide: https://github.com/apache/airflow/blob/1.10.11/UPDATIN...
공급사 Apache
제품 Airflow's Experimental API
영향 버전 Apache Airflow <1.10.11, 0, < 1.10.11
수정 버전 1.10.11
Apply updates per vendor instructions.
조치 기한: 2022.07.18CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE CWE-1056, CWE-1188, CWE-306
KEV 등록일 2022.01.18
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://nvd.nist.gov/vuln/detail/CVE-2020-13927
EPSS 데이터 기준일 2026.06.27