Loading HuntDB...

GHSA-r7x6-xfcm-3mxv

GitHub Security Advisory

Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs.  This is a different issue than CVE-2023-42663 but leading to similar outcome.
Users of Apache Airflow are advised to upgrade to version 2.7.3 or newer to mitigate the risk associated with this vulnerability.

Affected Packages

PyPI apache-airflow
Affected versions: 0 (fixed in 2.7.3)

Related CVEs

Key Information

GHSA ID
GHSA-r7x6-xfcm-3mxv
Published
November 12, 2023 3:30 PM
Last Modified
November 18, 2024 4:26 PM
CVSS Score
7.5 /10
Primary Ecosystem
PyPI
Primary Package
apache-airflow
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.