Skip to content

Apache Airflow information disclosure vulnerability

Moderate severity GitHub Reviewed Published Jul 12, 2023 to the GitHub Advisory Database • Updated Sep 11, 2024

Package

pip apache-airflow (pip)

Affected versions

< 2.6.3

Patched versions

2.6.3

Description

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Connection edit view. This vulnerability is considered low since it requires someone with access to Connection resources specifically updating the connection to exploit it. Users should upgrade to version 2.6.3 or later which has removed the vulnerability.

References

Published by the National Vulnerability Database Jul 12, 2023
Published to the GitHub Advisory Database Jul 12, 2023
Reviewed Jul 12, 2023
Last updated Sep 11, 2024

Severity

Moderate

EPSS score

0.052%
(21st percentile)

Weaknesses

CVE ID

CVE-2022-46651

GHSA ID

GHSA-xvw9-3mhm-xjqq

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.