Apache Airflow
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*
- < 3.2.0
A vulnerability exists in Apache Airflow versions prior to 3.2.0, where SQL error stack traces were exposed through the API, regardless of the 'api/expose_stack_traces' setting. This exposure could provide additional information to potential attackers.
The vulnerability could lead to the unintentional disclosure of sensitive information, such as SQL statements and error details, which could be leveraged by an attacker.
Users are advised to upgrade to Apache Airflow version 3.2.0 or later, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.