PT-2024-4257 · Apache · Apache Airflow

Jens Scheffler

·

Published

2024-06-13

·

Updated

2024-12-11

·

CVE-2024-25142

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 2.9.2
Description The issue is related to the use of web browser cache containing sensitive information in Apache Airflow. Airflow did not return a "Cache-Control" header for dynamic content, which could result in potentially storing sensitive data in the local cache of the browser. This could allow an attacker to disclose protected information through the Cache-Control header.
Recommendations For Apache Airflow versions prior to 2.9.2, upgrade to version 2.9.2, which fixes the issue. As a temporary workaround, consider configuring the browser to disable caching of sensitive data or restricting access to sensitive information until the issue is resolved.

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-04744
BIT-AIRFLOW-2024-25142
CVE-2024-25142
GHSA-9XPJ-62MM-24H2
PYSEC-2024-195

Affected Products

Apache Airflow