Airflow 2.72.8.4 Authenticated UI Exposes Provider Config (CVE-2024-31869)
CVE-2024-31869 Published on April 18, 2024
Airflow versions 2.7.0 through 2.8.4 have a vulnerability that allows an authenticated user to see sensitive provider configuration via the "configuration" UI page when "non-sensitive-only" was set as "webserver.expose_config" configuration (The celery provider is the only community provider currently that has sensitive configurations). You should migrate to Airflow 2.9 or change your "expose_config" configuration to False as a workaround. This is similar, but different to CVE-2023-46288 https://github.com/advisories/GHSA-9qqg-mh7c-chfq which concerned API, not UI configuration page.
Vulnerability Analysis
CVE-2024-31869 can be exploited with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2024-31869 has been classified to as an Information Disclosure vulnerability or weakness.
Products Associated with CVE-2024-31869
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2024-31869 are published in Apache AirFlow:
Affected Versions
Apache Software Foundation Apache Airflow:- Version 2.7.0, <= 2.8.4 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.