Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2522-mrjc-m688

Опубликовано: 18 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used

Airflow versions 2.7.0 through 2.8.4 have a vulnerability that allows an authenticated user to see sensitive provider configuration via the "configuration" UI page when "non-sensitive-only" was set as "webserver.expose_config" configuration (The celery provider is the only community provider currently that has sensitive configurations). You should migrate to Airflow 2.9 or change your "expose_config" configuration to False as a workaround. This is similar, but different to CVE-2023-46288 https://github.com/advisories/GHSA-9qqg-mh7c-chfq which concerned API, not UI configuration page.

Пакеты

Наименование

apache-airflow

pip
Затронутые версииВерсия исправления

>= 2.7.0, < 2.9.0

2.9.0

EPSS

Процентиль: 5%
0.00025
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
nvd
больше 1 года назад

Airflow versions 2.7.0 through 2.8.4 have a vulnerability that allows an authenticated user to see sensitive provider configuration via the "configuration" UI page when "non-sensitive-only" was set as "webserver.expose_config" configuration (The celery provider is the only community provider currently that has sensitive configurations). You should migrate to Airflow 2.9 or change your "expose_config" configuration to False as a workaround. This is similar, but different to CVE-2023-46288 https://github.com/advisories/GHSA-9qqg-mh7c-chfq which concerned API, not UI configuration page.

CVSS3: 4.3
debian
больше 1 года назад

Airflow versions 2.7.0 through 2.8.4 have a vulnerability that allows ...

CVSS3: 4.3
fstec
больше 1 года назад

Уязвимость программное обеспечение создания, мониторинга и оркестрации сценариев обработки данных Apache Airflow, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 5%
0.00025
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200