CVE-2022-46651

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Connection edit view. This vulnerability is considered low since it requires someone with access to Connection resources specifically updating the connection to exploit it. Users should upgrade to version 2.6.3 or later which has removed the vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

History

20 Jul 2023, 15:34

Type Values Removed Values Added
CPE cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*
CWE CWE-200 NVD-CWE-noinfo
First Time Apache
Apache airflow
References (MISC) https://lists.apache.org/thread/n45h3y82og125rnlgt6rbm9szfb6q24d - (MISC) https://lists.apache.org/thread/n45h3y82og125rnlgt6rbm9szfb6q24d - Mailing List, Patch, Vendor Advisory
References (MISC) https://github.com/apache/airflow/pull/32309 - (MISC) https://github.com/apache/airflow/pull/32309 - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

12 Jul 2023, 12:46

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-12 10:15

Updated : 2023-12-10 15:14


NVD link : CVE-2022-46651

Mitre link : CVE-2022-46651

CVE.ORG link : CVE-2022-46651


JSON object : View

Products Affected

apache

  • airflow
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor