Apache Airflow 2.7.0/2.7.1 Config Disclosure via expose_config
CVE-2023-45348 Published on October 14, 2023

Apache Airflow: Configuration information leakage vulnerability
Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the "expose_config" option is set to "non-sensitive-only". The `expose_config` option is False by default. It is recommended to upgrade to a version that is not affected.

Vendor Advisory NVD

Weakness Type

What is an Information Disclosure Vulnerability?

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CVE-2023-45348 has been classified to as an Information Disclosure vulnerability or weakness.


Products Associated with CVE-2023-45348

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2023-45348 are published in Apache AirFlow:

 

Affected Versions

Apache Software Foundation Apache Airflow:

Exploit Probability

EPSS
0.41%
Percentile
60.70%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.