CVE-2023-46215
published 2023-10-28CVE-2023-46215: Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow. Sensitive information logged as clear text…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.20%
64.7th percentile
Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow.
Sensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend
Note: the vulnerability is about the information exposed in the logs not about accessing the logs.
This issue affects Apache Airflow Celery provider: from 3.3.0 through 3.4.0; Apache Airflow: from 1.10.0 through 2.6.3.
Users are recommended to upgrade Airflow Celery provider to version 3.4.1 and Apache Airlfow to version 2.7.0 which fixes the issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | >= 1.10.0 < 2.7.0 | 2.7.0 |
| apache | airflow_celery_provider | 3.3.0 – 3.4.0 | — |
| apache_software_foundation | apache_airflow | >= 1.10.0 < 2.7.0 | 2.7.0 |
| apache_software_foundation | apache_airflow_celery_provider | 3.3.0 – 3.4.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
ghsa·2023-10-28
CVE-2023-46215 [HIGH] CWE-532 Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow.
Sensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend
Note: the vulnerability is about the information exposed in the logs not about accessing the logs.
This issue affects Apache Airflow Celery provider: from 3.3.0 through 3.4.0; Apache Airflow: from 1.10.0 through 2.6.3.
Users are recommended to upgrade Airflow Celery provider to version 3.4.1 and Apache Airlfow to version 2.7.0 which fixes the issue.
OSV
Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
osv·2023-10-28
CVE-2023-46215 [HIGH] Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow.
Sensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend
Note: the vulnerability is about the information exposed in the logs not about accessing the logs.
This issue affects Apache Airflow Celery provider: from 3.3.0 through 3.4.0; Apache Airflow: from 1.10.0 through 2.6.3.
Users are recommended to upgrade Airflow Celery provider to version 3.4.1 and Apache Airlfow to version 2.7.0 which fixes the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2023/10/28/1https://github.com/apache/airflow/pull/34954https://lists.apache.org/thread/wm1jfmks7r6m7bj0mq4lmw3998svn46nhttp://www.openwall.com/lists/oss-security/2023/10/28/1https://github.com/apache/airflow/pull/34954https://lists.apache.org/thread/wm1jfmks7r6m7bj0mq4lmw3998svn46n
2023-10-28
Published