PT-2026-45370 · Apache · Apache Airflow
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Airflow versions prior to 3.2.2
Description
A bug in the Variable response masker allows the bypass of nested-key redaction when the nesting depth of a JSON value exceeds the recursion limit of the shared secrets masker. This occurs with key names suffixed by secrets, such as
password, token, secret, or api key, as the masker returns the original nested item before verifying the sensitive key name. An authenticated UI or API user with Variable read permissions can harvest plaintext secret values stored within deeply-nested JSON Variables.Recommendations
Update to version 3.2.2 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow