Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
High7.5CVE-2023-46215 · Published Oct 28, 2023 · updated Jul 13, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | >= 1.10.0, < 2.7.0 | 2.7.0 |
Details and references
Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow. Sensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend Note: the vulnerability is about the information exposed in the logs not about accessing the logs. This issue affects Apache Airflow Celery provider: from 3.3.0 through 3.4.0; Apache Airflow: from 1.10.0 through 2.6.3. Users are recommended to upgrade Airflow Celery provider to version 3.4.1 and Apache Airlfow to version 2.7.0 which fixes the issue.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-532
- Also known as
- BIT-airflow-2023-46215, CVE-2023-46215, PYSEC-2026-1131, PYSEC-2026-2364
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 232023 | Apache Airflow vulnerable to Exposure of Sensitive Information CVE-2023-46288Medium4.3fixed in 2.7.2 | Medium4.3 | 2.7.2 |
| Oct 142023 | Apache Airflow vulnerable to sensitive information exposure CVE-2023-42663Medium6.5fixed in 2.7.2 | Medium6.5 | 2.7.2 |
| Oct 142023 | Apache Airflow vulnerable to sensitive information exposure when users list warnings for all DAGs CVE-2023-42780Medium6.5fixed in 2.7.2 | Medium6.5 | 2.7.2 |
| Oct 142023 | Apache Airflow vulnerable to sensitive information exposure when expose-config is set to non-sensitive-only CVE-2023-45348Medium4.3fixed in 2.7.2 | Medium4.3 | 2.7.2 |
| Oct 142023 | Apache Airflow vulnerable to privilege escalation CVE-2023-42792Medium6.5fixed in 2.7.2 | Medium6.5 | 2.7.2 |
| Nov 122023 | Apache Airflow allows authenticated and DAG-view authorized users to modify some DAG run detail values when submitting notes CVE-2023-47037Medium4.3fixed in 2.7.3 | Medium4.3 | 2.7.3 |