QID 996889
Date Published: 2024-01-25
QID 996889: Python (Pip) Security Update for apache-airflow (GHSA-mg2x-mggj-6955)
Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any encryption. Additionally, if used with an Airflow version between 2.3.0 and 2.6.0, the configuration dictionary will be logged as plain text in the triggerer service without masking. This allows anyone with access to the metadata or triggerer log to obtain the configuration file and use it to access the Kubernetes cluster.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-mg2x-mggj-6955 for updates and patch information.
Vendor References
- GHSA-mg2x-mggj-6955 -
github.com/advisories/GHSA-mg2x-mggj-6955
CVEs related to QID 996889
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mg2x-mggj-6955 | apache-airflow |
|