PT-2023-8626 · Apache · Apache Airflow

Hussein Awala

+1

·

Published

2023-10-14

·

Updated

2024-05-01

·

CVE-2023-45348

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions 2.7.0 through 2.7.1
Description The issue allows an authenticated user to retrieve sensitive configuration information when the expose config option is set to "non-sensitive-only". The expose config option is False by default. Approximately 39,118 devices may be affected.
Recommendations For Apache Airflow versions 2.7.0 and 2.7.1, it is recommended to upgrade to a version that is not affected. As a temporary workaround, consider setting the expose config option to False to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-01279
BIT-AIRFLOW-2023-45348
CVE-2023-45348
GHSA-FPXX-XV4C-GXQP
PYSEC-2023-204

Affected Products

Apache Airflow