PT-2020-15028 · Apache · Airflow

Ali Al-Habsi

·

Published

2020-12-14

·

Updated

2024-03-06

·

CVE-2020-17511

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Airflow versions prior to 1.10.13
Description The issue occurs when creating a user using the airflow CLI or when creating a Connection with a password field in Airflow, where the password gets logged in plain text in the Log table in Airflow Metadata.
Recommendations For versions prior to 1.10.13, update to version 1.10.13 or later to resolve the issue.

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2020-17511
CVE-2020-17511
GHSA-CVCQ-GMC3-Q6M8
PYSEC-2020-262

Affected Products

Airflow