CVE-2023-46288
Last modified
CVE-2023-46288 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.4.0 to 2.7.0. Sensitive configuration information has been exposed to authenticated users with the ability to read configuration via Airflow REST API for configuration even when the expose_config option is set to non-sensitive-only. The expose_config option is False by default. EPSS estimates a 1.42% chance of exploitation in the next 30 days.
Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.4.0 to 2.7.0. Sensitive configuration information has been exposed to authenticated users with the ability to read configuration via Airflow REST API for configuration even when the expose_config option is set to non-sensitive-only. The expose_config option is False by default. It is recommended to upgrade to a version that is not affected if you set expose_config to non-sensitive-only configuration. This is a different error than CVE-2023-45348 which allows authenticated user to retrieve individual configuration values in 2.7.* by specially crafting their request (solved in 2.7.2). Users are recommended to upgrade to version 2.7.2, which fixes the issue and additionally fixes CVE-2023-45348.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Airflow | >= 2.4.0, < 2.7.0 |
References
- https://lists.apache.org/thread/yw4vzm0c5lqkwm0bxv6qy03yfd1od4nwMailing List, Patch, Vendor Advisory
- https://lists.apache.org/thread/yw4vzm0c5lqkwm0bxv6qy03yfd1od4nwMailing List, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-46288?
How severe is CVE-2023-46288?
How do I fix CVE-2023-46288?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-46281A vulnerability has been identified in Opcenter Execution Fo…8.8
- CVE-2023-46282A vulnerability has been identified in Opcenter Execution Fo…6.1
- CVE-2023-46283A vulnerability has been identified in Opcenter Execution Fo…7.5
- CVE-2023-46284A vulnerability has been identified in Opcenter Execution Fo…7.5
- CVE-2023-46285A vulnerability has been identified in Opcenter Execution Fo…7.5
- CVE-2023-46287XSS exists in NagVis before 1.9.38 via the select function i…6.1
- CVE-2023-46289 Rockwell Automation FactoryTalk View Site Edition insuffici…7.5
- CVE-2023-4629The LadiApp plugin for WordPress is vulnerable to Cross-Site…4.3
- CVE-2023-46290 Due to inadequate code logic, a previously unauthenticated …8.1
- CVE-2023-46294An issue was discovered in Teledyne FLIR M300 2.00-19. User …3.4
- CVE-2023-46295An issue was discovered in Teledyne FLIR M300 2.00-19. Unaut…9.8
- CVE-2023-46297An issue was discovered on Mercusys MW325R EU V3 MW325R(EU)_…5.1
Are you affected by CVE-2023-46288?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
