Skip to content
Apache AirflowGHSA-r7x6-xfcm-3mxv

Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

High6.5CVE-2023-42781 · Published Nov 12, 2023 · updated Nov 24, 2024

Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs.  This is a different issue than CVE-2023-42663 but leading to similar outcome. Users of Apache Airflow are advised to upgrade to version 2.7.3 or newer to mitigate the risk associated with this vulnerability.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.7.32.7.3
Details and references

More Apache Airflow advisories

All Apache Airflow

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.