PT-2024-3091 · Airflow · Airflow
Jarek Potiuk
+1
·
Published
2024-04-17
·
Updated
2024-05-01
·
CVE-2024-31869
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Airflow versions 2.7.0 through 2.8.4
Description
The issue is related to insufficient protection of internal data, allowing an authenticated user to access sensitive provider configuration via the "configuration" UI page when the "non-sensitive-only" option is set as "webserver.expose config" configuration. This primarily affects the Celery provider, which has sensitive configurations.
Recommendations
For Airflow versions 2.7.0 through 2.8.4, migrate to Airflow 2.9 or change the "expose config" configuration to False as a workaround.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Airflow