CVE-2022-46651
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Connection edit view.
Does this matter?
Lower severity and a low EPSS score (1.20%). Track it; it rarely justifies an emergency change on its own.
Description
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Connection edit view. This vulnerability is considered low since it requires someone with access to Connection resources specifically updating the connection to exploit it. Users should upgrade to version 2.6.3 or later which has removed the vulnerability.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.20% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apache/airflow
- Source
- security@apache.org
References
- https://github.com/apache/airflow/pull/32309Patch
- https://lists.apache.org/thread/n45h3y82og125rnlgt6rbm9szfb6q24dMailing List, Patch, Vendor Advisory
- https://github.com/apache/airflow/pull/32309Patch
- https://lists.apache.org/thread/n45h3y82og125rnlgt6rbm9szfb6q24dMailing List, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.