PT-2023-8626 · Apache · Apache Airflow
Hussein Awala
+1
·
Published
2023-10-14
·
Updated
2024-05-01
·
CVE-2023-45348
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Airflow versions 2.7.0 through 2.7.1
Description
The issue allows an authenticated user to retrieve sensitive configuration information when the
expose config option is set to "non-sensitive-only". The expose config option is False by default. Approximately 39,118 devices may be affected.Recommendations
For Apache Airflow versions 2.7.0 and 2.7.1, it is recommended to upgrade to a version that is not affected. As a temporary workaround, consider setting the
expose config option to False to minimize the risk of exploitation.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow