First published: Wed Sep 21 2022(Updated: )
In Apache Airflow 2.3.0 through 2.3.4, part of a url was unnecessarily formatted, allowing for possible information extraction.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Airflow | >=2.3.0<=2.3.4 | |
pip/apache-airflow | >=2.3.0<2.4.0rc1 | 2.4.0rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40604 is a vulnerability in Apache Airflow 2.3.0 through 2.3.4 that allows for possible information extraction via a formatted URL.
The severity of CVE-2022-40604 is high, with a CVSS severity score of 7.5.
To fix CVE-2022-40604, upgrade to version 2.4.0b1 or higher of Apache Airflow.
You can find more information about CVE-2022-40604 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-40604), [GitHub Pull Request](https://github.com/apache/airflow/pull/26337), [PYSEC Advisory](https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2022-279.yaml).
CWE-134 is a vulnerability category related to uncontrolled format string, which is relevant to CVE-2022-40604.