Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the "expose_config" option is set to "non-sensitive-only". The `expose_config` option is False by default.
It is recommended to upgrade to a version that is not affected.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2023-10-14T09:46:44.563Z
Updated: 2024-09-17T15:27:12.016Z
Reserved: 2023-10-08T19:34:31.046Z
Link: CVE-2023-45348
Vulnrichment
Updated: 2024-08-02T20:21:16.332Z
NVD
Status : Modified
Published: 2023-10-14T10:15:10.473
Modified: 2024-11-21T08:26:46.790
Link: CVE-2023-45348
Redhat
No data.