apache-airflow is vulnerable to Exposure of Sensitive Information
60
Medium Risk
The Config API does not mask team-scoped sensitive configuration values in multi-team deployments. The masker matches only base section and option names and does not normalise team-prefixed sections before the sensitivity check. A user with configuration-read access can read a team-scoped Celery broker URL, including embedded credentials, in clear text while the equivalent global option is masked. The fix normalises team-scoped sections before masking.
You are affected if you are using a version that falls within the vulnerable range and you run multi-team mode and expose the Config API to users with configuration-read access.
apache-airflow is vulnerable to Exposure of Sensitive Information in versions 3.3.0 - 3.3.0.
Upgrade the apache-airflow library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant