Lucene search

K
osvGoogleOSV:GHSA-2522-MRJC-M688
HistoryApr 18, 2024 - 9:30 a.m.

Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used

2024-04-1809:30:44
Google
osv.dev
13
apache airflow
configuration vulnerability
sensitive data
authenticated user
ui page
cve-2023-46288

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

18.8%

Airflow versions 2.7.0 through 2.8.4 have a vulnerability that allows an authenticated user to see sensitive provider configuration via the β€œconfiguration” UI pageΒ when β€œnon-sensitive-only” was set as β€œwebserver.expose_config” configuration (The celery provider is the only community provider currently that has sensitive configurations). You should migrate to Airflow 2.9 or change your β€œexpose_config” configuration to False as a workaround. This is similar, but different to CVE-2023-46288 https://github.com/advisories/GHSA-9qqg-mh7c-chfq which concerned API, not UI configuration page.

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

18.8%