S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2020-13927 Scanner

Detects 'Improper Access Control' vulnerability in Apache Airflow affects v. <1.10.11.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
4.3k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-13927
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and is documented at https://airflow.apache.org/docs/1.10.11/security.html#api-authentication. Note this change fixes it for new installs but existing users need to change their config to default `[api]auth_backend = airflow.api.auth.backend.deny_all` as mentioned in the Updating Guide: https://github.com/apache/airflow/blob/1.10.11/UPDATING.md#experimental-api-will-deny-all-request-by-default

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Apache Airflowby n/a
Apache Airflow <1.10.11
airflowby apache
AFFECTED< 1.10.11SAFE ✓≥ 1.10.11
Updated Aug 21, 2026View on NVD →
Detail

Apache Airflow is an open source platform used for managing and scheduling complex workflows. It is primarily used for data engineering and data science tasks, allowing users to automate the execution of data pipelines and workflows. With Airflow, users can easily create, manage and monitor workflows through a graphical user interface that enables drag-and-drop functionality. 

Recently, a security vulnerability (CVE-2020-13927) has been identified in Airflow's Experimental API. Previously, the default setting for the API allowed all requests without authentication, making it highly vulnerable to security risks. The vulnerability allows an attacker to execute arbitrary code remotely and take control over the infected system, giving them access to sensitive data and causing irreversible damages to the system. 

When exploited, this vulnerability can lead to highly compromised systems, making it easier for attackers to steal sensitive data, implant malware, or cause service disruptions that can cost a company heavily in terms of reputation and financial loss. The vulnerability can affect any organization using Airflow's Experimental API and is a significant risk that must be addressed. 

s4e.io, with its pro features, is an excellent platform for individuals and businesses to enhance their digital security and maintain a secure environment. With s4e.io, users can easily learn about vulnerabilities in their digital assets, mitigate risks, and safeguard important data. By emphasizing the importance of digital security, individuals and businesses can protect themselves against the myriad of security threats that exist online.

 

REFERENCES

Solution Advice

As a precautionary measure, users can take the following steps to protect against this vulnerability: 

  • Upgrade Airflow to version 1.10.11 
  • Change the default configuration to: [api] auth_backend = airflow.api.auth.backend.deny_all 
  • Explore third-party security tools that can monitor and detect threats in real-time 
  • Train employees on effective security measures to protect against vulnerabilities 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.