QID 996889

Date Published: 2024-01-25

QID 996889: Python (Pip) Security Update for apache-airflow (GHSA-mg2x-mggj-6955)

Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any encryption. Additionally, if used with an Airflow version between 2.3.0 and 2.6.0, the configuration dictionary will be logged as plain text in the triggerer service without masking. This allows anyone with access to the metadata or triggerer log to obtain the configuration file and use it to access the Kubernetes cluster.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-mg2x-mggj-6955 for updates and patch information.
    Vendor References

    CVEs related to QID 996889

    Software Advisories
    Advisory ID Software Component Link
    GHSA-mg2x-mggj-6955 apache-airflow URL Logo github.com/advisories/GHSA-mg2x-mggj-6955