Loading HuntDB...

CVE-2023-45348

UNKNOWN
Published 2023-10-14T09:46:44.563Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2023-45348. We'll provide specific mitigation strategies based on your environment and risk profile.

No CVSS data available

Description

Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the "expose_config" option is set to "non-sensitive-only". The `expose_config` option is False by default.
It is recommended to upgrade to a version that is not affected.

Available Exploits

No exploits available for this CVE.

Related News

No news articles found for this CVE.

Affected Products

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

✓ GitHub Reviewed MODERATE

Apache Airflow vulnerable to sensitive information exposure when expose-config is set to non-sensitive-only

GHSA-fpxx-xv4c-gxqp

Advisory Details

Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the `expose_config` option is set to `non-sensitive-only`. The `expose_config` option is `False` by default. It is recommended to upgrade to a version that is not affected.

Affected Packages

PyPI apache-airflow
ECOSYSTEM: ≥2.7.0 <2.7.2

CVSS Scoring

CVSS Score

5.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Advisory provided by GitHub Security Advisory Database. Published: October 14, 2023, Modified: March 6, 2024

References

Published: 2023-10-14T09:46:44.563Z
Last Modified: 2025-02-13T17:14:03.098Z
Copied to clipboard!