Skip to content
Apache AirflowGHSA-fpxx-xv4c-gxqp

Apache Airflow vulnerable to sensitive information exposure when expose-config is set to non-sensitive-only

Medium4.3CVE-2023-45348 · Published Oct 14, 2023 · updated Mar 7, 2024

Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the `expose_config` option is set to `non-sensitive-only`. The `expose_config` option is `False` by default. It is recommended to upgrade to a version that is not affected.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
>= 2.7.0, < 2.7.22.7.2
Details and references

More Apache Airflow advisories

All Apache Airflow

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.