apache-airflow is vulnerable to Exposure of Sensitive Information
65
Medium Risk
The Config API surfaces per-key secrets-backend environment overrides as synthetic configuration options. Those option names are absent from the sensitive-values list, so the masker does not redact them. A user with configuration-read access can read plaintext secrets-backend credentials such as Vault role_id and secret_id. The fix removes the synthetic options from Config API output.
You are affected if you are using a version that falls within the vulnerable range and you configure a secrets backend through per-key environment overrides and expose the Config API to users with configuration-read access.
apache-airflow is vulnerable to Exposure of Sensitive Information in versions 3.2.0 - 3.2.2.
Upgrade the apache-airflow library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant