CVE-2023-45348 Information
Oct 16, 2023
cve
Description
Apache Airflow versions 2.7.0 and 2.7.1 is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the xpose_config\ option is set to
on-sensitive-only. The expose_config option is False by default.
It is recommended to upgrade to a version that is not affected.
Reference
https://lists.apache.org/thread/sy4l5d6tn58hr8r61r2fkt1f0qock9z9 https://github.com/apache/airflow/pull/34712
Share on: