Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44052
HistoryOct 30, 2023 - 5:27 a.m.

Information Disclosure

2023-10-3005:27:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
information disclosure
airflow
celery
rediss
amqp
rpc
sensitive information
software security

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

6.5

Confidence

High

EPSS

0.005

Percentile

77.5%

apache_airflow_providers_celery is vulnerable to Information Disclosure. An attacker is able to exploit this vulnerability by tricking a user into running an Airflow job that contains a malicious Celery task. The malicious task would then insert sensitive information into the Airflow logs as clear text when rediss, amqp or rpc protocols are used resulting in exposure of confidential information.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

6.5

Confidence

High

EPSS

0.005

Percentile

77.5%