We found results for “”
CVE-2025-62503
Good to know:
Date: October 30, 2025
Privilege boundary bypass Apache Airflow 3.0.0 before 3.1.1: User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Execution with Unnecessary Privileges
CWE-250Top Fix
Upgrade Version
Upgrade to version apache-airflow-core - 3.1.1;apache-airflow-core - 3.1.1;apache-airflow - 3.1.1;https://github.com/apache/airflow.git - 3.1.1
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | LOW |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


