CVE-2024-50378

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Nov 8, 2024
CWE ID 201

Summary

CVE-2024-50378 is a vulnerability affecting Airflow versions before 2.10.3. This issue grants authenticated users with audit log access unauthorized access to sensitive values in the audit logs. Sensitive variables set via Airflow CLI were appearing in the audit log and stored unencrypted in the Airflow database. Although the risk is limited to users with audit log access, it is strongly advised to upgrade to Airflow 2.10.3 or a later version to mitigate this issue. Users who previously used the CLI to set secret variables should manually delete related entries from the log table.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Apache Airflow

Affected Vendors

  • Apache Software Foundation