Apache Airflow
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*
- < 3.1.6
A vulnerability exists in Apache Airflow versions prior to 3.1.6, where proxy fields within a Connection may contain URLs with embedded authentication details. These fields were not automatically masked in log outputs, leading to potential exposure of proxy credentials when such connections are logged. Users are advised to upgrade to version 3.1.6 or later, which addresses this issue.
Exposed proxy credentials in log files, potentially leading to unauthorized access or misuse of proxy services.
Upgrade to Apache Airflow version 3.1.6 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.