Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xvw9-3mhm-xjqq

Опубликовано: 12 июл. 2023
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Apache Airflow information disclosure vulnerability

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Connection edit view. This vulnerability is considered low since it requires someone with access to Connection resources specifically updating the connection to exploit it. Users should upgrade to version 2.6.3 or later which has removed the vulnerability.

Пакеты

Наименование

apache-airflow

pip
Затронутые версииВерсия исправления

< 2.6.3

2.6.3

EPSS

Процентиль: 30%
0.00109
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 лет назад

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Connection edit view. This vulnerability is considered low since it requires someone with access to Connection resources specifically updating the connection to exploit it. Users should upgrade to version 2.6.3 or later which has removed the vulnerability.

CVSS3: 6.5
debian
около 2 лет назад

Apache Airflow, versions before 2.6.3, is affected by a vulnerability ...

CVSS3: 6.5
fstec
около 2 лет назад

Уязвимость программное обеспечение создания, мониторинга и оркестрации сценариев обработки данных Airflow, связанная с раскрытием защищаемой информации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 30%
0.00109
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-200