CVE-2023-45348 Information

Description

Apache Airflow versions 2.7.0 and 2.7.1 is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the xpose_config\ option is set to on-sensitive-only. The expose_config option is False by default. It is recommended to upgrade to a version that is not affected.

Reference

https://lists.apache.org/thread/sy4l5d6tn58hr8r61r2fkt1f0qock9z9 https://github.com/apache/airflow/pull/34712

Share on: