In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has can_create permissions on DAG Runs can create Dag Runs for dags that they dont have edit permissions for.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Airflow | Apache | 1.10.0 (including) | 1.10.15 (including) |
| Airflow | Apache | 2.0.0 (including) | 2.2.0 (excluding) |