Information Exposure Affecting apache-airflow package, versions [2.4.0,2.7.0b1)
Threat Intelligence
EPSS
0.05% (23rd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-APACHEAIRFLOW-6028125
- published 24 Oct 2023
- disclosed 23 Oct 2023
- credit Wei Lee, id_No2015429
Introduced: 23 Oct 2023
CVE-2023-46288 Open this link in a new tabHow to fix?
Upgrade apache-airflow
to version 2.7.0b1 or higher.
Overview
apache-airflow is a platform to programmatically author, schedule, and monitor workflows.
Affected versions of this package are vulnerable to Information Exposure through the REST API for configuration. An attacker can gain access to sensitive configuration information by reading the configuration, even when the expose_config
option is set to non-sensitive-only
.
References
CVSS Scores
version 3.1