imPC@ndo IT

Tracker / CVE-2022-40604

CVE-2022-40604

High 7.5

In Apache Airflow 2.3.0 through 2.3.4, part of a url was unnecessarily formatted, allowing for possible information extraction.

Affected products and versions

apache airflow · 2.3.0 → 2.3.4

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References