PT-2024-4257 · Apache · Apache Airflow
Jens Scheffler
·
Published
2024-06-13
·
Updated
2024-12-11
·
CVE-2024-25142
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Airflow versions prior to 2.9.2
Description
The issue is related to the use of web browser cache containing sensitive information in Apache Airflow. Airflow did not return a "Cache-Control" header for dynamic content, which could result in potentially storing sensitive data in the local cache of the browser. This could allow an attacker to disclose protected information through the Cache-Control header.
Recommendations
For Apache Airflow versions prior to 2.9.2, upgrade to version 2.9.2, which fixes the issue. As a temporary workaround, consider configuring the browser to disable caching of sensitive data or restricting access to sensitive information until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow