First published: Mon Nov 14 2022(Updated: )
A vulnerability in UI of Apache Airflow allows an attacker to view unmasked secrets in rendered template values for tasks which were not executed (for example when they were depending on past and previous instances of the task failed). This issue affects Apache Airflow prior to 2.3.1.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Airflow | <2.3.1 | |
pip/apache-airflow | <2.3.1 | 2.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-27949 is high with a CVSS score of 7.5.
CVE-2022-27949 is a vulnerability in the UI of Apache Airflow that allows an attacker to view unmasked secrets in rendered template values for tasks which were not executed.
CVE-2022-27949 affects Apache Airflow prior to version 2.3.1.
An attacker can exploit CVE-2022-27949 by accessing the UI of Apache Airflow and viewing unmasked secrets in rendered template values for tasks which were not executed.
To fix CVE-2022-27949, it is recommended to upgrade to Apache Airflow version 2.3.1 or later.