Apache Airflow subject to Exposure of Sensitive Information
High severity
GitHub Reviewed
Published
Nov 14, 2022
to the GitHub Advisory Database
•
Updated Sep 11, 2024
Description
Published by the National Vulnerability Database
Nov 14, 2022
Published to the GitHub Advisory Database
Nov 14, 2022
Reviewed
Nov 16, 2022
Last updated
Sep 11, 2024
A vulnerability in UI of Apache Airflow allows an attacker to view unmasked secrets in rendered template values for tasks which were not executed (for example when they were depending on past and previous instances of the task failed). This issue affects Apache Airflow prior to 2.3.1.
References