Apache Airflow
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*
- >= 3.1.0, < 3.1.4
A vulnerability exists in Apache Airflow versions 3.1.0 prior to 3.1.4, allowing authenticated UI users to see secret values in rendered templates. This issue arises because secrets were not adequately redacted, potentially exposing them to users without the necessary authorization.
The vulnerability could lead to unauthorized exposure of sensitive secret values to users in the UI.
Users are advised to upgrade to Apache Airflow version 3.1.4, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.