CyberRota Analysis
AI-GeneratedApache Airflow's secrets masker is vulnerable as it fails to mask dictionary values in the Rendered Templates UI, exposing sensitive information stored as JSON Variables to users with access to that view. This could lead to unauthorized disclosure of secrets, posing a significant risk to data confidentiality. Organizations using Apache Airflow should prioritize upgrading to version 3.3.1 or later to mitigate this vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in cleartext to any user with access to that task's Rendered Templates view. Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.
Related CVEs
Other vulnerabilities affecting the same vendor(s)