CVE-2023-45348
published 2023-10-14CVE-2023-45348: Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when…
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
1.23%
65.5th percentile
Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the "expose_config" option is set to "non-sensitive-only". The `expose_config` option is False by default.
It is recommended to upgrade to a version that is not affected.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | >= 2.4.0 < 2.7.0 | 2.7.0 |
| apache | airflow | >= 2.7.0 < 2.7.2 | 2.7.2 |
| apache_software_foundation | apache_airflow | >= 2.4.0 < 2.7.0 | 2.7.0 |
| apache_software_foundation | apache_airflow | 2.7.0 – 2.8.4 | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
ghsa4.3MEDIUM
osv4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Airflow vulnerable to Exposure of Sensitive Information
osv·2023-10-23·CVSS 4.3
CVE-2023-46288 [MEDIUM] Apache Airflow vulnerable to Exposure of Sensitive Information
Apache Airflow vulnerable to Exposure of Sensitive Information
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow. This issue affects Apache Airflow from 2.4.0 to 2.7.0.
Sensitive configuration information has been exposed to authenticated users with the ability to read configuration via Airflow REST API for configuration even when the expose_config option is set to non-sensitive-only. The expose_config option is False by default. It is recommended to upgrade to a version that is not affected if you set expose_config to non-sensitive-only configuration. This is a different error than CVE-2023-45348 which allows authenticated user to retrieve individual configuration values in 2.7.* by specially crafting their request (solved in 2.7.2).
Users are r
GHSA
Apache Airflow vulnerable to Exposure of Sensitive Information
ghsa·2023-10-23·CVSS 4.3
CVE-2023-46288 [MEDIUM] CWE-200 Apache Airflow vulnerable to Exposure of Sensitive Information
Apache Airflow vulnerable to Exposure of Sensitive Information
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow. This issue affects Apache Airflow from 2.4.0 to 2.7.0.
Sensitive configuration information has been exposed to authenticated users with the ability to read configuration via Airflow REST API for configuration even when the expose_config option is set to non-sensitive-only. The expose_config option is False by default. It is recommended to upgrade to a version that is not affected if you set expose_config to non-sensitive-only configuration. This is a different error than CVE-2023-45348 which allows authenticated user to retrieve individual configuration values in 2.7.* by specially crafting their request (solved in 2.7.2).
Users are r
OSV
CVE-2023-46288: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow
osv·2023-10-23·CVSS 4.3
CVE-2023-46288 [MEDIUM] CVE-2023-46288: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.4.0 to 2.7.0.
Sensitive configuration information has been exposed to authenticated users with the ability to read configuration via Airflow REST API for configuration even when the expose_config option is set to non-sensitive-only. The expose_config option is False by default. It is recommended to upgrade to a version that is not affected if you set expose_config to non-sensitive-only configuration. This is a different error than CVE-2023-45348 which allows authenticated user to retrieve individual configuration values in 2.7.* by specially crafting their request (solved in 2.7.2).
Users are recommended to upgrade to version 2.7.2, which fixes the issue and
OSV
CVE-2023-45348: Apache Airflow, versions 2
osv·2023-10-14
CVE-2023-45348 CVE-2023-45348: Apache Airflow, versions 2
Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the "expose_config" option is set to "non-sensitive-only". The `expose_config` option is False by default.
It is recommended to upgrade to a version that is not affected.
OSV
Apache Airflow vulnerable to sensitive information exposure when expose-config is set to non-sensitive-only
osv·2023-10-14
CVE-2023-45348 [MEDIUM] Apache Airflow vulnerable to sensitive information exposure when expose-config is set to non-sensitive-only
Apache Airflow vulnerable to sensitive information exposure when expose-config is set to non-sensitive-only
Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the `expose_config` option is set to `non-sensitive-only`. The `expose_config` option is `False` by default. It is recommended to upgrade to a version that is not affected.
GHSA
Apache Airflow vulnerable to sensitive information exposure when expose-config is set to non-sensitive-only
ghsa·2023-10-14
CVE-2023-45348 [MEDIUM] CWE-200 Apache Airflow vulnerable to sensitive information exposure when expose-config is set to non-sensitive-only
Apache Airflow vulnerable to sensitive information exposure when expose-config is set to non-sensitive-only
Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the `expose_config` option is set to `non-sensitive-only`. The `expose_config` option is `False` by default. It is recommended to upgrade to a version that is not affected.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2023/10/23/2https://github.com/apache/airflow/pull/34712https://lists.apache.org/thread/sy4l5d6tn58hr8r61r2fkt1f0qock9z9http://www.openwall.com/lists/oss-security/2023/10/23/2https://github.com/apache/airflow/pull/34712https://lists.apache.org/thread/sy4l5d6tn58hr8r61r2fkt1f0qock9z9
2023-10-14
Published