PT-2023-8625 · Apache · Apache Airflow

Klexadoc

·

Publicado

2023-09-12

·

Atualizado

2026-02-20

·

CVE-2023-40712

CVSS v4.0

7.1

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 2.7.1
Description The issue allows authenticated users who have access to see the task/dag in the UI to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be masked in the UI. This is related to the disclosure of protected information.
Recommendations For Apache Airflow versions prior to 2.7.1, upgrade to version 2.7.1 or later, which has removed the vulnerability.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-01278
BIT-AIRFLOW-2023-40712
CVE-2023-40712
GHSA-MJQH-V5F2-G2MW
PYSEC-2023-171

Produtos afetados

Apache Airflow