Skip to content
Apache AirflowGHSA-xvw9-3mhm-xjqq

Apache Airflow information disclosure vulnerability

High6.5CVE-2022-46651 · Published Jul 12, 2023 · updated Feb 13, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.6.32.6.3
Details and references

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Connection edit view. This vulnerability is considered low since it requires someone with access to Connection resources specifically updating the connection to exploit it. Users should upgrade to version 2.6.3 or later which has removed the vulnerability.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-200
Also known as
BIT-airflow-2022-46651, CVE-2022-46651, PYSEC-2023-103

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Jul 122023Apache Airflow Incorrect Authorization vulnerability
CVE-2023-35908High6.5fixed in 2.6.3
Jul 122023Apache Airflow Improper Input Validation vulnerability
CVE-2023-36543High6.5fixed in 2.6.3
Jul 122023Apache Airflow Improper Input Validation vulnerability
CVE-2023-22888High6.5fixed in 2.6.3
Jul 122023Apache Airflow Path Traversal vulnerability
CVE-2023-22887High6.5fixed in 2.6.3
Jun 192023Apache Airflow vulnerable to exposure of sensitive information
CVE-2023-35005High6.5fixed in 2.6.2rc1
Aug 52023Apache Airflow Execution with Unnecessary Privileges
CVE-2023-39508High8.8fixed in 2.6.0b1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.