Vulnerability Description
User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Airflow | >= 3.0.0, < 3.1.1 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/3v58249qscyn1hg240gh8hqg9pb4okcrMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2025/10/29/8Mailing ListThird Party Advisory
FAQ
What is CVE-2025-62503?
CVE-2025-62503 is a vulnerability with a CVSS score of 4.6 (MEDIUM). User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.
How severe is CVE-2025-62503?
CVE-2025-62503 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-62503?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Airflow.