{"api_version":"1","generated_at":"2026-07-23T13:02:18+00:00","cve":"CVE-2023-40712","urls":{"html":"https://cve.report/CVE-2023-40712","api":"https://cve.report/api/cve/CVE-2023-40712.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-40712","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-40712"},"summary":{"title":"CVE-2023-40712","description":"Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be masked in the UI.\n\nUsers are strongly advised to upgrade to version 2.7.1 or later which has removed the vulnerability.","state":"PUBLIC","assigner":"security@apache.org","published_at":"2023-09-12 12:15:00","updated_at":"2023-09-13 03:50:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://github.com/apache/airflow/pull/33512","name":"https://github.com/apache/airflow/pull/33512","refsource":"MISC","tags":[],"title":"Set strict to True when parsing dates in webserver views by hussein-awala · Pull Request #33512 · apache/airflow · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.apache.org/thread/jw1yv4lt6hpowqbb0x4o3tdp0jhx2bts","name":"https://lists.apache.org/thread/jw1yv4lt6hpowqbb0x4o3tdp0jhx2bts","refsource":"MISC","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/apache/airflow/pull/33516","name":"https://github.com/apache/airflow/pull/33516","refsource":"MISC","tags":[],"title":"Stop adding values to rendered templates UI when there is no dagrun by hussein-awala · Pull Request #33516 · apache/airflow · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-40712","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40712","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"40712","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"airflow","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-40712","ASSIGNER":"security@apache.org","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be masked in the UI.\n\nUsers are strongly advised to upgrade to version 2.7.1 or later which has removed the vulnerability."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-200 Exposure of Sensitive Information to an Unauthorized Actor","cweId":"CWE-200"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Apache Software Foundation","product":{"product_data":[{"product_name":"Apache Airflow","version":{"version_data":[{"version_affected":"<","version_name":"0","version_value":"2.7.1"}]}}]}}]}},"references":{"reference_data":[{"url":"https://github.com/apache/airflow/pull/33512","refsource":"MISC","name":"https://github.com/apache/airflow/pull/33512"},{"url":"https://github.com/apache/airflow/pull/33516","refsource":"MISC","name":"https://github.com/apache/airflow/pull/33516"},{"url":"https://lists.apache.org/thread/jw1yv4lt6hpowqbb0x4o3tdp0jhx2bts","refsource":"MISC","name":"https://lists.apache.org/thread/jw1yv4lt6hpowqbb0x4o3tdp0jhx2bts"}]},"generator":{"engine":"Vulnogram 0.1.0-dev"},"source":{"discovery":"UNKNOWN"},"credits":[{"lang":"en","value":"klexadoc"}]},"nvd":{"publishedDate":"2023-09-12 12:15:00","lastModifiedDate":"2023-09-13 03:50:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*","versionEndExcluding":"2.7.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}