First published: Wed Mar 15 2023(Updated: )
Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Airflow | <2.5.2 | |
pip/apache-airflow | <2.5.2rc1 | 2.5.2rc1 |
<2.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25695 is a vulnerability in Apache Airflow that allows the generation of error messages containing sensitive information.
CVE-2023-25695 affects Apache Airflow versions before 2.5.2.
The severity of CVE-2023-25695 is medium with a CVSS score of 5.3.
To fix CVE-2023-25695, update your Apache Airflow installation to version 2.5.2 or later.
CWE-209 is a vulnerability category that refers to information exposure through an error message.