Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Klexadoc

#38993of 53,625
7.1Total CVSS
Vulnerabilities · 1
PT-2023-8625
7.1
2023-09-12
Apache · Apache Airflow · CVE-2023-40712
**Name of the Vulnerable Software and Affected Versions** Apache Airflow versions prior to 2.7.1 **Description** The issue allows authenticated users who have access to see the task/dag in the UI to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be masked in the UI. This is related to the disclosure of protected information. **Recommendations** For Apache Airflow versions prior to 2.7.1, upgrade to version 2.7.1 or later, which has removed the vulnerability.