漏洞描述 鉴权绕过漏洞是指攻击者通过某些手段绕过系统的正常权限验证机制,获取未授权的访问或执行权限。这种漏洞通常存在于身份验证、授权检查、权限控制等环节的不足或缺陷中,使得未经授权的用户能够访问或操作敏感数据、执行关键操作,甚至获取系统控制权。
相关漏洞推荐 POC CVE-2020-11978: Apache Airflow <=1.10.10 - Remote Code Execution POC CVE-2020-17526: Apache Airflow <1.10.14 - Authentication Bypass POC CVE-2021-38540: Apache Airflow - Unauthenticated Variable Import POC CVE-2022-24288: Apache Airflow OS Command Injection POC CVE-2020-11981: Apache Airflow <=1.10.10 - Command Injection POC CVE-2020-17526: Apache Airflow <1.10.14 - Authentication Bypass POC airflow-default-login: Apache Airflow Default Login POC airflow-v3-default-login: Apache Airflow v3 Default Login POC airflow-configuration-exposure: Apache Airflow Configuration Page - Detect Apache Airflow admin 未授权访问漏洞 (CVE-2020-17526) Apache Airflow Experimental API身份验证绕过漏洞 Apache Airflow CVE-2020-11978远程代码执行漏洞 Apache Airflow CVE-2022-24288 命令注入漏洞