CVE-2020-13927
Apache Airflow
Published 10 Nov 2020 · updated 17 Jun 2026 · Analyzed
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 18 Jan 2022, with a remediation deadline of 18 Jul 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and is documented at https://airflow.apache.org/docs/1.10.11/security.html#api-authentication. Note this change fixes it for new installs but existing users need to change their config to default `[api]auth_backend = airflow.api.auth.backend.deny_all` as mentioned in the Updating Guide: https://github.com/apache/airflow/blob/1.10.11/UPDATING.md#experimental-api-will-deny-all-request-by-default
References
- packetstormsecurity.com/files/162908/Apache-Airflow-1.10.10-Remote-Code-Execution.html · Exploit, Third Party Advisory, VDB Entry
- packetstormsecurity.com/files/174764/Apache-Airflow-1.10.10-Remote-Code-Execution.html · Exploit, Third Party Advisory, VDB Entry
- lists.apache.org/thread.html/r23a81b247aa346ff193670be565b2b8ea4b17ddbc7a35fc099c1aadd%40%3Cdev.airflow.apache.org%3E · Mailing List, Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-13927 · Third Party Advisory, US Government Resource