Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-25695: Do not show version/node in UI traceback for unauthenticated user by potiuk · Pull Request #29501 · apache/airflow

Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2.

CVE
#vulnerability#apache#auth

The traceback contains information that might be useful for a potential attacker to better target their attack (Python/Airflow version, node name). This information should not be shown if traceback is shown to unauthenticated user.

potiuk deleted the redact-version-node-information-for-non-authenticated-users branch

February 13, 2023 09:24

ephraimbuddy pushed a commit that referenced this pull request

Mar 7, 2023

…9501)

The traceback contains information that might be useful for a potential attacker to better target their attack (Python/Airflow version, node name). This information should not be shown if traceback is shown to unauthenticated user.

(cherry picked from commit cf81455)

pierrejeambrun pushed a commit that referenced this pull request

Mar 7, 2023

…9501)

The traceback contains information that might be useful for a potential attacker to better target their attack (Python/Airflow version, node name). This information should not be shown if traceback is shown to unauthenticated user.

(cherry picked from commit cf81455)

pierrejeambrun pushed a commit that referenced this pull request

Mar 8, 2023

…9501)

The traceback contains information that might be useful for a potential attacker to better target their attack (Python/Airflow version, node name). This information should not be shown if traceback is shown to unauthenticated user.

(cherry picked from commit cf81455)

sirVir pushed a commit to sirVir/airflow that referenced this pull request

Mar 14, 2023

…ache#29501)

The traceback contains information that might be useful for a potential attacker to better target their attack (Python/Airflow version, node name). This information should not be shown if traceback is shown to unauthenticated user.

Related news

GHSA-h6g5-wqqr-3mw3: Sensitive Information in Error Messages in Apache Airflow

Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2. The traceback contains information that might be useful for a potential attacker to better target their attack (Python/Airflow version, node name). This information should not be shown if traceback is shown to unauthenticated user.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907