Apache AirflowGHSA-32wr-qqw6-5mfp
Apache Airflow vulnerable to sensitive information exposure
Medium6.5CVE-2023-42663 · Published Oct 14, 2023 · updated Feb 13, 2025
Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user with access to read specific DAGs _only_ to read information about task instances in other DAGs. Users of Apache Airflow are advised to upgrade to version 2.7.2 or newer to mitigate the risk associated with this vulnerability.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | < 2.7.2 | 2.7.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-200
- Also known as
- BIT-airflow-2023-42663, CVE-2023-42663, PYSEC-2023-197
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Nov 122023 | Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor | High6.5 | 2.7.3 |
| Oct 282023 | Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability | High7.5 | 2.7.0 |
| Oct 232023 | Apache Airflow vulnerable to Exposure of Sensitive Information | Medium4.3 | 2.7.2 |
| Oct 142023 | Apache Airflow vulnerable to sensitive information exposure when users list warnings for all DAGs | Medium6.5 | 2.7.2 |
| Oct 142023 | Apache Airflow vulnerable to sensitive information exposure when expose-config is set to non-sensitive-only | Medium4.3 | 2.7.2 |
| Oct 142023 | Apache Airflow vulnerable to privilege escalation | Medium6.5 | 2.7.2 |