apache-airflow is vulnerable to Exposure of Sensitive Information
33
Low Risk
The /ui/dependencies scheduling graph applies the caller's readable-Dag filter to the top-level Dag key but still emits referenced Dag identifiers in the dep.source and dep.target fields of trigger and sensor entries. A user can enumerate identifiers of Dags they are not authorized to read. This is a residual gap left after an earlier fix that filtered only the top-level key. The fix propagates the filter into the dependency fields.
You are affected if you are using a version that falls within the vulnerable range and you rely on per-Dag read scoping to keep Dag identifiers private across teams.
apache-airflow is vulnerable to Exposure of Sensitive Information in versions 3.0.0 - 3.2.2.
Upgrade the apache-airflow library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant