apache-airflow-core is vulnerable to Cleartext Storage of Sensitive Information
65
Medium Risk
Airflow's secrets masker skips masking for Variable values stored under the var.json namespace when the stored value is a dict. Rendered logs and UI views can then display a dict-valued secret Variable in cleartext instead of redacting it. Anyone with log or UI access to a task that reads such a Variable can read its underlying secret contents. The fix extends the masker's redaction path to cover dict-valued var.json entries.
You are affected if you are using a version that falls within the vulnerable range and store secret values in a Variable whose value is a JSON dict, since those values may appear unmasked in logs or the UI.
apache-airflow-core is vulnerable to Cleartext Storage of Sensitive Information in versions 0.0.1 - 3.3.0.
Upgrade the apache-airflow-core and/or the apache-airflow library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.