Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mjqh-v5f2-g2mw

Опубликовано: 12 сент. 2023
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Apache Airflow information exposure vulnerability

Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be masked in the UI.

Users are strongly advised to upgrade to version 2.7.1 or later which has removed the vulnerability.

Пакеты

Наименование

apache-airflow

pip
Затронутые версииВерсия исправления

< 2.7.1

2.7.1

EPSS

Процентиль: 34%
0.00136
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be masked in the UI. Users are strongly advised to upgrade to version 2.7.1 or later which has removed the vulnerability.

CVSS3: 6.5
debian
больше 2 лет назад

Apache Airflow, versions before 2.7.1, is affected by a vulnerability ...

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость программное обеспечение создания, мониторинга и оркестрации сценариев обработки данных Airflow, связанная с раскрытием защищаемой информации, позволяющая нарушителю раскрыть конфигурацию произвольной задачи

EPSS

Процентиль: 34%
0.00136
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-200