oss-sec mailing list archives
CVE-2023-25956: Apache Airflow AWS Provider: Arbitrary file read via AWS provider
From: Jarek Potiuk <potiuk () apache org>
Date: Thu, 23 Feb 2023 17:48:43 +0000
Severity: moderate Description: Generation of Error Message Containing Sensitive Information vulnerability in the Apache Airflow AWS Provider. This issue affects Apache Airflow AWS Provider versions before 7.2.1. Credit: Son Tran from VNPT - VCI (finder) References: https://github.com/apache/airflow/pull/29587 https://airflow.apache.org/ https://www.cve.org/CVERecord?id=CVE-2023-25956
Current thread:
- CVE-2023-25956: Apache Airflow AWS Provider: Arbitrary file read via AWS provider Jarek Potiuk (Feb 23)