Apache Airflow
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*
- >= 3.1.0, < 3.1.6
A vulnerability in Apache Airflow versions prior to 3.1.6 allows sensitive values to be exposed in cleartext within the Rendered Templates UI. This issue arises when rendered template fields in a DAG exceed the maximum templated field length, leading to truncation. The problem occurs because the serialization of these fields utilizes a secrets masker that does not incorporate user-defined mask_secret patterns, resulting in inadequate masking of sensitive information before it is truncated and displayed.
This vulnerability could lead to the unintentional exposure of sensitive information in the Rendered Templates UI, where parts of secret values could be visible in cleartext.
Users are advised to upgrade to Apache Airflow version 3.1.6 or later, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.