Apache

Airflow

162 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.61%
  • Veröffentlicht 12.08.2026 15:32:10
  • Zuletzt bearbeitet 16.09.2026 15:17:41

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_des...

  • EPSS 0.27%
  • Veröffentlicht 12.08.2026 15:31:26
  • Zuletzt bearbeitet 16.09.2026 15:17:40

Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configuration-read acces...

  • EPSS 0.15%
  • Veröffentlicht 12.08.2026 15:27:46
  • Zuletzt bearbeitet 16.09.2026 15:17:41

Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `N...

  • EPSS 0.15%
  • Veröffentlicht 12.08.2026 15:26:40
  • Zuletzt bearbeitet 16.09.2026 15:17:42

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only ...

  • EPSS 0.17%
  • Veröffentlicht 12.08.2026 15:24:53
  • Zuletzt bearbeitet 16.09.2026 15:17:42

Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value wa...

  • EPSS 0.15%
  • Veröffentlicht 12.08.2026 15:24:10
  • Zuletzt bearbeitet 16.09.2026 15:17:42

Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A team-aware ...

  • EPSS 0.22%
  • Veröffentlicht 12.08.2026 15:23:22
  • Zuletzt bearbeitet 16.09.2026 16:17:14

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a team name con...

  • EPSS 0.99%
  • Veröffentlicht 07.07.2026 09:20:18
  • Zuletzt bearbeitet 08.07.2026 19:37:10

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain remote code ...

  • EPSS 0.41%
  • Veröffentlicht 07.07.2026 09:19:36
  • Zuletzt bearbeitet 16.09.2026 15:17:37

In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator passed a secret (for example a provider API key) into its trigger, any authentica...

  • EPSS 0.41%
  • Veröffentlicht 07.07.2026 09:18:53
  • Zuletzt bearbeitet 16.09.2026 15:17:35

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not fir...