Apache AirflowGHSA-r7x6-xfcm-3mxv
Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
High6.5CVE-2023-42781 · Published Nov 12, 2023 · updated Nov 24, 2024
Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs. This is a different issue than CVE-2023-42663 but leading to similar outcome. Users of Apache Airflow are advised to upgrade to version 2.7.3 or newer to mitigate the risk associated with this vulnerability.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | < 2.7.3 | 2.7.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-200
- Also known as
- BIT-airflow-2023-42781, CVE-2023-42781, PYSEC-2023-231
- nvd.nist.gov/vuln/detail/CVE-2023-42781
- github.com/apache/airflow/pull/34939
- github.com/apache/airflow/commit/33ec72948f74f56f2adb5e2d388e60e88e8a3fa3
- github.com/apache/airflow
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2023-231.yaml
- lists.apache.org/thread/7dnl8nszdxqyns57f3dw0sloy5dfl9o1
- www.openwall.com/lists/oss-security/2023/11/12/2
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Nov 122023 | Apache Airflow: improper authorization | Medium4.3 | 2.7.3 |
| Oct 282023 | Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability | High7.5 | 2.7.0 |
| Oct 232023 | Apache Airflow vulnerable to Exposure of Sensitive Information | Medium4.3 | 2.7.2 |
| Oct 142023 | Apache Airflow vulnerable to sensitive information exposure | Medium6.5 | 2.7.2 |
| Oct 142023 | Apache Airflow vulnerable to sensitive information exposure when users list warnings for all DAGs | Medium6.5 | 2.7.2 |
| Oct 142023 | Apache Airflow vulnerable to sensitive information exposure when expose-config is set to non-sensitive-only | Medium4.3 | 2.7.2 |