Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r7x6-xfcm-3mxv

Опубликовано: 12 нояб. 2023
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs.  This is a different issue than CVE-2023-42663 but leading to similar outcome. Users of Apache Airflow are advised to upgrade to version 2.7.3 or newer to mitigate the risk associated with this vulnerability.

Пакеты

Наименование

apache-airflow

pip
Затронутые версииВерсия исправления

< 2.7.3

2.7.3

EPSS

Процентиль: 19%
0.00059
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 лет назад

Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs.  This is a different issue than CVE-2023-42663 but leading to similar outcome. Users of Apache Airflow are advised to upgrade to version 2.7.3 or newer to mitigate the risk associated with this vulnerability.

CVSS3: 6.5
debian
около 2 лет назад

Apache Airflow, versions before 2.7.3, has a vulnerability that allows ...

CVSS3: 4.3
fstec
около 2 лет назад

Уязвимость сетевого программного средства Apache Airflow, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 19%
0.00059
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-200