apache-airflow is vulnerable to Exposure of Sensitive Information
55
Medium Risk
The Task SDK masks Variable values only when the deserialized value is a string or a dict. A Variable whose JSON value is a top-level list matches neither branch and is returned unmasked in task logs and the Rendered Templates view. Any user able to read those logs or rendered templates can recover secrets stored in that shape. The fix extends masking to list-shaped values.
You are affected if you are using a version that falls within the vulnerable range and an authenticated user can read task logs or the Rendered Templates view for tasks that reference a list-shaped Variable holding secrets.
apache-airflow is vulnerable to Exposure of Sensitive Information in versions 3.0.2 - 3.3.0.
Upgrade the apache-airflow library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant