Apache Airflow
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*
- < 3.1.4
A vulnerability exists in Apache Airflow versions prior to 3.1.4, where the error-reporting UI could inadvertently expose full keyword arguments (kwargs) passed to operators in the event of a Directed Acyclic Graph (DAG) parsing failure. If these kwargs included sensitive information, such as secrets, this data could be visible in the UI tracebacks to authenticated users with permission to view the DAG.
Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive information, such as secrets, to authenticated users via the Airflow UI.
Users are advised to upgrade to Apache Airflow versions 3.1.4 or 2.11.1.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.