PT-2023-8625 · Apache · Apache Airflow
Klexadoc
·
Publicado
2023-09-12
·
Atualizado
2026-02-20
·
CVE-2023-40712
CVSS v4.0
7.1
Alta
| Vetor | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Apache Airflow versions prior to 2.7.1
Description
The issue allows authenticated users who have access to see the task/dag in the UI to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be masked in the UI. This is related to the disclosure of protected information.
Recommendations
For Apache Airflow versions prior to 2.7.1, upgrade to version 2.7.1 or later, which has removed the vulnerability.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Airflow