Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs.  This is a different issue than CVE-2023-42663 but leading to similar outcome. Users of Apache Airflow are advised to upgrade to version 2.7.3 or newer to mitigate the risk associated with this vulnerability.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2023-11-12T13:14:09.700Z

Updated: 2024-09-03T15:22:21.819Z

Reserved: 2023-09-14T07:01:50.218Z

Link: CVE-2023-42781

cve-icon Vulnrichment

Updated: 2024-08-02T19:30:24.179Z

cve-icon NVD

Status : Analyzed

Published: 2023-11-12T14:15:25.847

Modified: 2023-11-20T19:33:07.527

Link: CVE-2023-42781

cve-icon Redhat

No data.