CVE-2023-25695

CWE-2095 documents4 sources
Severity
5.3MEDIUM
EPSS
1.2%
top 21.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 15

Description

Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

NVDapache/airflow< 2.5.2
PyPIapache-airflow< 2.5.2rc1+1

Patches

🔴Vulnerability Details

4
OSV
Sensitive Information in Error Messages in Apache Airflow2023-03-15
CVEList
Information disclosure in Apache Airflow2023-03-15
GHSA
Sensitive Information in Error Messages in Apache Airflow2023-03-15
OSV
CVE-2023-25695: Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow2023-03-15
CVE-2023-25695 (MEDIUM CVSS 5.3) | Generation of Error Message Contain | cvebase.io