CVE-2023-45348
Apache Airflow: Configuration information leakage vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the "expose_config" option is set to "non-sensitive-only". The `expose_config` option is False by default.
It is recommended to upgrade to a version that is not affected.
Apache Airflow, versiones 2.7.0 y 2.7.1, se ve afectada por una vulnerabilidad que permite a un usuario autenticado recuperar información de configuración confidencial cuando la opción "expose_config" está configurada en "non-sensitive-only". La opción `expose_config` es "Falso" de forma predeterminada. Se recomienda actualizar a una versión que no se vea afectada.
Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the "expose_config" option is set to "non-sensitive-only". The `expose_config` option is False by default. It is recommended to upgrade to a version that is not affected.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-10-08 CVE Reserved
- 2023-10-14 CVE Published
- 2025-02-13 CVE Updated
- 2025-07-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2023/10/23/2 | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/apache/airflow/pull/34712 | 2023-11-16 |
URL | Date | SRC |
---|---|---|
https://lists.apache.org/thread/sy4l5d6tn58hr8r61r2fkt1f0qock9z9 | 2023-11-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Airflow Search vendor "Apache" for product "Airflow" | >= 2.7.0 < 2.7.2 Search vendor "Apache" for product "Airflow" and version " >= 2.7.0 < 2.7.2" | - |
Affected
|