Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs
Vulnerability Description
In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator passed a secret (for example a provider API key) into its trigger, any authenticated user with DAG-scoped task-instance read access for that DAG could read that secret in clear text while the task was deferred. Users should upgrade to apache-airflow 3.3.0 or later, which masks sensitive values in trigger kwargs returned by the API.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
Apache Airflow 信息泄露漏洞
Vulnerability Description
Apache Software Foundation Apache Airflow是Apache Software Foundation基金会的开源工作流调度与数据管道编排平台。 Apache Airflow 3.3.0之前版本存在信息泄露漏洞,该漏洞源于REST API任务实例详情和列表端点未对延迟任务的触发器kwargs进行掩码处理,可能导致已认证用户以明文读取敏感信息。以下版本受到影响:3.3.0之前版本。
CVSS Information
N/A
Vulnerability Type
N/A