Sensitive Information in Error Messages in Apache Airflow
Moderate severity
GitHub Reviewed
Published
Mar 15, 2023
to the GitHub Advisory Database
•
Updated Sep 11, 2024
Description
Published by the National Vulnerability Database
Mar 15, 2023
Published to the GitHub Advisory Database
Mar 15, 2023
Reviewed
Mar 16, 2023
Last updated
Sep 11, 2024
Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2. The traceback contains information that might be useful for a potential attacker to better target their attack (Python/Airflow version, node name). This information should not be shown if traceback is shown to unauthenticated user.
References