Apache

Airflow

91 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 26.09.2025 08:15:38
  • Zuletzt bearbeitet 01.10.2025 15:23:03

Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict access to sensitive connection fields to Connection Editing Users, effectively applying a "write-only" model for sensitive values...

  • EPSS 2.61%
  • Veröffentlicht 15.11.2024 09:15:14
  • Zuletzt bearbeitet 03.06.2025 21:12:28

Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability allows DAG authors to unintentionally or intentionally log sensitive configuration variables. Unauthori...

  • EPSS 0.27%
  • Veröffentlicht 08.11.2024 15:15:06
  • Zuletzt bearbeitet 10.07.2025 21:39:16

Airflow versions before 2.10.3 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive variables were set via airflow CLI, values of those variables ap...

  • EPSS 1.47%
  • Veröffentlicht 07.09.2024 08:15:11
  • Zuletzt bearbeitet 03.06.2025 21:12:43

Example DAG: example_inlet_event_extra.py shipped with Apache Airflow version 2.10.0 has a vulnerability that allows an authenticated attacker with only DAG trigger permission to execute arbitrary commands. If you used that example as the base of you...

  • EPSS 0.69%
  • Veröffentlicht 07.09.2024 08:15:11
  • Zuletzt bearbeitet 03.06.2025 21:12:55

Apache Airflow versions before 2.10.1 have a vulnerability that allows DAG authors to add local settings to the DAG folder and get it executed by the scheduler, where the scheduler is not supposed to execute code submitted by the DAG author. Users a...

  • EPSS 0.26%
  • Veröffentlicht 21.08.2024 16:15:08
  • Zuletzt bearbeitet 20.03.2025 21:15:21

Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider to be installed on...

  • EPSS 0.05%
  • Veröffentlicht 17.07.2024 08:15:02
  • Zuletzt bearbeitet 21.11.2024 09:28:28

Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that could execute arbitrary code in the scheduler context, which should be forbidden according to the Air...

  • EPSS 0.23%
  • Veröffentlicht 17.07.2024 08:15:01
  • Zuletzt bearbeitet 21.11.2024 09:28:26

Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider. Users are recommended to upgrade to version 2.9.3, which fixes this issue.

  • EPSS 0.1%
  • Veröffentlicht 14.06.2024 09:15:09
  • Zuletzt bearbeitet 20.03.2025 20:15:31

Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.  Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local...

  • EPSS 2.55%
  • Veröffentlicht 14.05.2024 16:17:01
  • Zuletzt bearbeitet 27.03.2025 20:15:26

Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.  Users are recommended to upgrade to version 2.9.1, which fixes this issue.