Safety vulnerability ID: 65396
The information on this page was manually curated by our Cybersecurity Intelligence Team.
A vulnerability has been identified in versions of Airflow where, by using deferrable mode and a Kubernetes configuration file for authentication, the Airflow worker sends this configuration as an unencrypted dictionary to the triggerer, storing it in metadata. This process, coupled with certain Airflow versions, also results in the unmasked logging of the configuration dictionary in the triggerer service. Consequently, unauthorized individuals could potentially access and exploit the Kubernetes cluster using the exposed configuration details.
Latest version: 10.0.1
Provider package apache-airflow-providers-cncf-kubernetes for Apache Airflow
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application