Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1052 | Airflow versions 2.7.0 through 2.8.4 have a vulnerability that allows an authenticated user to see sensitive provider configuration via the "configuration" UI page when "non-sensitive-only" was set as "webserver.expose_config" configuration (The celery provider is the only community provider currently that has sensitive configurations). You should migrate to Airflow 2.9 or change your "expose_config" configuration to False as a workaround. This is similar, but different to CVE-2023-46288 https://github.com/advisories/GHSA-9qqg-mh7c-chfq which concerned API, not UI configuration page. |
Github GHSA |
GHSA-2522-mrjc-m688 | Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used |
Thu, 13 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 11 Feb 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache airflow |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache airflow |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-03-13T16:10:23.130Z
Reserved: 2024-04-06T19:52:15.124Z
Link: CVE-2024-31869
Updated: 2024-08-02T01:59:50.558Z
Status : Modified
Published: 2024-04-18T08:15:38.037
Modified: 2025-03-13T17:15:30.837
Link: CVE-2024-31869
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA