CVE-2024-50378

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-50378
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-50378.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-50378
Aliases
Published
2024-11-08T15:15:06Z
Modified
2024-11-12T07:57:05.862528Z
Summary
[none]
Details

Airflow versions before 2.10.3 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive variables were set via airflow CLI, values of those variables appeared in the audit log and were stored unencrypted in the Airflow database. While this risk is limited to users with audit log access, it is recommended to upgrade to Airflow 2.10.3 or a later version, which addresses this issue. Users who previously used the CLI to set secret variables should manually delete entries with those variables from the log table.

References

Affected packages

Git / github.com/apache/airflow

Affected ranges

Type
GIT
Repo
https://github.com/apache/airflow
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

constraints-2-3

constraints-2.*

constraints-2.0.0rc1
constraints-2.0.0rc2
constraints-2.0.0rc3
constraints-2.0.1rc1
constraints-2.1.0rc1
constraints-2.10.0
constraints-2.10.0b1
constraints-2.10.0b2
constraints-2.10.0rc1
constraints-2.10.1
constraints-2.10.1rc1
constraints-2.10.2
constraints-2.10.2rc1
constraints-2.10.3rc1
constraints-2.2.0b1
constraints-2.2.0b2
constraints-2.2.0rc1
constraints-2.3.0b1
constraints-2.3.0rc1
constraints-2.3.0rc2
constraints-2.4.0b1