apache-airflow is vulnerable to Exposure of Sensitive Information
65
Medium Risk
The REST API task-instance detail and list endpoints return a deferred task's trigger kwargs without masking. Secrets passed into a trigger, such as a provider API key, are returned in clear text while the task is deferred. Any user with task-instance read access for the Dag can read them. The fix always returns empty trigger kwargs ("{}") from the API.
You are affected if you are using a version that falls within the vulnerable range and you expose the REST API to authenticated users and run deferred operators that pass secrets into trigger kwargs.
apache-airflow is vulnerable to Exposure of Sensitive Information in versions 2.5.0 - 3.2.2.
Upgrade the apache-airflow library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant