Executive Summary

Informations
Name CVE-2024-31869 First vendor Publication 2024-04-18
Vendor Cve Last vendor Modification 2025-03-13

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Overall CVSS Score 4.3
Base Score 4.3 Environmental Score 4.3
impact SubScore 1.4 Temporal Score 4.3
Exploitabality Sub Score 2.8
 
Attack Vector Network Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact Low
Integrity Impact None Availability Impact None
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

Airflow versions 2.7.0 through 2.8.4 have a vulnerability that allows an authenticated user to see sensitive provider configuration via the "configuration" UI pageĀ when "non-sensitive-only" was set as "webserver.expose_config" configuration (The celery provider is the only community provider currently that has sensitive configurations). You should migrate to Airflow 2.9 or change your "expose_config" configuration to False as a workaround. This is similar, but different to CVE-2023-46288 https://github.com/advisories/GHSA-9qqg-mh7c-chfq which concerned API, not UI configuration page.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-31869

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 3

Sources (Detail)

http://www.openwall.com/lists/oss-security/2024/04/17/10
https://github.com/apache/airflow/pull/38795
https://lists.apache.org/thread/pz6vg7wcjk901rmsgt86h76g6kfcgtk3
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
Date Informations
2025-03-13 21:21:45
  • Multiple Updates
2025-02-11 21:21:15
  • Multiple Updates
2024-11-25 09:26:02
  • Multiple Updates
2024-05-02 00:27:28
  • Multiple Updates
2024-04-18 17:28:08
  • Multiple Updates
2024-04-18 13:27:38
  • First insertion