CVE-2022-40604
7.5HIGHIn Apache Airflow 2.3.0 through 2.3.4, part of a url was unnecessarily formatted, allowing for possible information extraction.
Published: 9/21/2022Updated: 5/27/2025
Description
In Apache Airflow 2.3.0 through 2.3.4, part of a url was unnecessarily formatted, allowing for possible information extraction.
AI AnalysisPowered by AI
Affected Products
apacheairflow
References
- https://github.com/apache/airflow/pull/26337PatchThird Party Advisory
- https://lists.apache.org/thread/z20x8m16fnhxdkoollv53w1ybsts687tVendor Advisory
- https://github.com/apache/airflow/pull/26337PatchThird Party Advisory
- https://lists.apache.org/thread/z20x8m16fnhxdkoollv53w1ybsts687tVendor Advisory