Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the expose_config
option is set to non-sensitive-only
. The expose_config
option is False
by default. It is recommended to upgrade to a version that is not affected.
{ "nvd_published_at": "2023-10-14T10:15:10Z", "cwe_ids": [ "CWE-200" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-10-17T02:43:58Z" }