First published: Thu Jun 13 2024(Updated: )
Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow. Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local cache of the browser. This issue affects Apache Airflow: before 2.9.2. Users are recommended to upgrade to version 2.9.2, which fixes the issue.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/apache-airflow | <2.9.2 | 2.9.2 |
Apache Airflow | <2.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25142 is considered a moderate-severity vulnerability due to the potential exposure of sensitive data in browser cache.
To fix CVE-2024-25142, you should upgrade your Apache Airflow installation to version 2.9.2 or later.
CVE-2024-25142 affects versions of Apache Airflow prior to 2.9.2 where sensitive information may be stored in the browser cache.
CVE-2024-25142 is primarily a client-side issue related to how browsers handle caching of sensitive information.
CVE-2024-25142 potentially exposes sensitive information that may be cached locally in the browser, such as credentials or personal data.