CVE-2023-25695
published 2023-03-15CVE-2023-25695: Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow…
PriorityP424medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
1.38%
68.9th percentile
Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | < 2.5.2 | 2.5.2 |
| apache_software_foundation | apache_airflow | < 2.5.2 | 2.5.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Sensitive Information in Error Messages in Apache Airflow
osv·2023-03-15
CVE-2023-25695 [MEDIUM] Sensitive Information in Error Messages in Apache Airflow
Sensitive Information in Error Messages in Apache Airflow
Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2. The traceback contains information that might be useful for a potential attacker to better target their attack (Python/Airflow version, node name). This information should not be shown if traceback is shown to unauthenticated user.
GHSA
Sensitive Information in Error Messages in Apache Airflow
ghsa·2023-03-15
CVE-2023-25695 [MEDIUM] CWE-209 Sensitive Information in Error Messages in Apache Airflow
Sensitive Information in Error Messages in Apache Airflow
Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2. The traceback contains information that might be useful for a potential attacker to better target their attack (Python/Airflow version, node name). This information should not be shown if traceback is shown to unauthenticated user.
OSV
CVE-2023-25695: Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow
osv·2023-03-15
CVE-2023-25695 CVE-2023-25695: Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow
Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-15
Published