apache-airflow is vulnerable to Exposure of Sensitive Information
65
Medium Risk
The bulk Variables API calls the redactor without passing the variable key, so the key-name check that hides secret-suffixed keys never fires for JSON-decodable values. A user with bulk Variable read access can read plaintext values of JSON variables whose keys would otherwise be redacted. This exposes credentials stored under names ending in _password, _token, or _secret. The fix passes the key so redaction applies to JSON values.
You are affected if you are using a version that falls within the vulnerable range and you store sensitive values in JSON-typed Variables under secret-suffixed key names and expose the bulk Variables API.
apache-airflow is vulnerable to Exposure of Sensitive Information in versions 3.0.0 - 3.2.2.
Upgrade the apache-airflow library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant