CVE-2023-42663Sensitive Information Exposure in Software Foundation Apache Airflow

Severity
6.5MEDIUMNVD
EPSS
0.5%
top 36.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14
Latest updateNov 13

Description

Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs. Users of Apache Airflow are advised to upgrade to version 2.7.2 or newer to mitigate the risk associated with this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

5
GHSA
Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor2023-11-12
GHSA
Apache Airflow vulnerable to sensitive information exposure2023-10-14
OSV
Apache Airflow vulnerable to sensitive information exposure2023-10-14
CVEList
Apache Airflow: Bypass permission verification to view task instances of other dags2023-10-14
OSV
CVE-2023-42663: Apache Airflow, versions before 22023-10-14

💬Community

1
HackerOne
CVE-2023-42663: Apache Airflow: Bypass permission verification to view task instances of other dags2023-11-13
CVE-2023-42663 — Sensitive Information Exposure | cvebase