Skip to content
Apache AirflowGHSA-h6g5-wqqr-3mw3

Sensitive Information in Error Messages in Apache Airflow

Medium5.3CVE-2023-25695 · Published Mar 15, 2023 · updated Feb 13, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.5.2rc12.5.2rc1
Details and references

Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2. The traceback contains information that might be useful for a potential attacker to better target their attack (Python/Airflow version, node name). This information should not be shown if traceback is shown to unauthenticated user.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-209
Also known as
BIT-airflow-2023-25695, CVE-2023-25695, PYSEC-2023-2

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Feb 242023Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider.
CVE-2023-25693Critical9.8fixed in 3.1.1
Apr 72023Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider: before 2.3.2.
CVE-2023-28707High7.5fixed in 2.3.2
Jan 212023Command Injection in Apache Airflow and Apache Airflow MySQL Provider
CVE-2023-22884Critical9.8fixed in 2.5.1
May 82023Apache Airflow vulnerable to stored Cross-site Scripting
CVE-2023-29247Medium5.4fixed in 2.6.0
May 82023Apache Airflow vulnerable to Privilege Context Switching Error
CVE-2023-25754Critical9.8fixed in 2.6.0b1
Jun 192023Apache Airflow vulnerable to exposure of sensitive information
CVE-2023-35005High6.5fixed in 2.6.2rc1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.