QID 995611
Date Published: 2023-10-18
QID 995611: Python (Pip) Security Update for apache-airflow (GHSA-fpxx-xv4c-gxqp)
Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the expose_config option is set to non-sensitive-only. The expose_config option is False by default. It is recommended to upgrade to a version that is not affected.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-fpxx-xv4c-gxqp for updates and patch information.
Vendor References
- GHSA-fpxx-xv4c-gxqp -
github.com/advisories/GHSA-fpxx-xv4c-gxqp
CVEs related to QID 995611
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fpxx-xv4c-gxqp | apache-airflow |
|