CVE-2023-46288 is a sensitive information exposure vulnerability affecting Apache Airflow versions 2.4.0 to 2.7.0. Authenticated users could access sensitive configuration details via the Airflow REST API, even when the expose_config option was set to non-sensitive-only. This vulnerability has a CVSS score of 4.3 (Medium), indicating low attack complexity and requiring authenticated access, with a potential impact of information disclosure. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE. Users are advised to upgrade to Apache Airflow version 2.7.2 to remediate this and a related vulnerability, CVE-2023-45348.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.0, < 2.7.0CPE matchmatch criteria | cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.