MEDIUM
Apache Airflow: Configuration information leakage vulnerability
Published Oct 14, 2023
4.3
MEDIUMCVSS 3.1
EPSS 1.23%
Description
Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the "expose_config" option is set to "non-sensitive-only". The `expose_config` option is False by default. It is recommended to upgrade to a version that is not affected.
Affected products
-
- Version 2.7.0StatusaffectedConstraints<2.7.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Airflow | unaffected |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://www.openwall.com/lists/oss-security/2023/10/23/2 Mailing ListThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-0024 Advisory
- https://github.com/advisories/GHSA-fpxx-xv4c-gxqp Advisory
- https://github.com/apache/airflow/commit/a4a0b5dd3d0ce05311c70bb9a32b66a650dbc0b4
- https://github.com/apache/airflow/pull/34712 patch
- https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2023-204.yaml
- https://lists.apache.org/thread/sy4l5d6tn58hr8r61r2fkt1f0qock9z9 vendor-advisoryMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-45348
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Oct 14, 2023
Updated Feb 13, 2025
Reserved Oct 8, 2023
Link CVE-2023-45348
CISA Vulnrichment
Updated Sep 17, 2024
ENISA EUVD
EUVD-2023-0024 GHSA-FPXX-XV4C-GXQP Assigner apache
Published Oct 14, 2023
Updated Feb 13, 2025
Exploited since n/a
Link EUVD-2023-0024