Apache AirflowGHSA-xvw9-3mhm-xjqq
Apache Airflow information disclosure vulnerability
High6.5CVE-2022-46651 · Published Jul 12, 2023 · updated Feb 13, 2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | < 2.6.3 | 2.6.3 |
Details and references
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Connection edit view. This vulnerability is considered low since it requires someone with access to Connection resources specifically updating the connection to exploit it. Users should upgrade to version 2.6.3 or later which has removed the vulnerability.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-200
- Also known as
- BIT-airflow-2022-46651, CVE-2022-46651, PYSEC-2023-103
- nvd.nist.gov/vuln/detail/CVE-2022-46651
- github.com/apache/airflow/pull/32309
- github.com/apache/airflow/commit/d01248382fe45a5f5a7fdeed4082a80c5f814ad8
- github.com/apache/airflow
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2023-103.yaml
- lists.apache.org/thread/n45h3y82og125rnlgt6rbm9szfb6q24d
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 122023 | Apache Airflow Incorrect Authorization vulnerability CVE-2023-35908High6.5fixed in 2.6.3 | High6.5 | 2.6.3 |
| Jul 122023 | Apache Airflow Improper Input Validation vulnerability CVE-2023-36543High6.5fixed in 2.6.3 | High6.5 | 2.6.3 |
| Jul 122023 | Apache Airflow Improper Input Validation vulnerability CVE-2023-22888High6.5fixed in 2.6.3 | High6.5 | 2.6.3 |
| Jul 122023 | Apache Airflow Path Traversal vulnerability CVE-2023-22887High6.5fixed in 2.6.3 | High6.5 | 2.6.3 |
| Jun 192023 | Apache Airflow vulnerable to exposure of sensitive information CVE-2023-35005High6.5fixed in 2.6.2rc1 | High6.5 | 2.6.2rc1 |
| Aug 52023 | Apache Airflow Execution with Unnecessary Privileges CVE-2023-39508High8.8fixed in 2.6.0b1 | High8.8 | 2.6.0b1 |