Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.3 PyPI

Sensitive Information in Error Messages in Apache Airflow

GHSA-h6g5-wqqr-3mw3 · BIT-airflow-2023-25695 · CVE-2023-25695 · PYSEC-2023-2

Published · Modified

Description

Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2. The traceback contains information that might be useful for a potential attacker to better target their attack (Python/Airflow version, node name). This information should not be shown if traceback is shown to unauthenticated user.

Ready to move

Start Securing

Free, no credit card | First findings in minutes