Severity: low

Affected versions:

- Apache Airflow before 2.6.3

Description:

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that 
allows an unauthorized actor to gain access to sensitive information in 
Connection edit view. This vulnerability is considered low since it requires 
someone with access to Connection resources specifically updating the 
connection to exploit it. Users should upgrade to version 2.6.3 or later which 
has removed the vulnerability.

References:

https://github.com/apache/airflow/pull/32309
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2022-46651


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to