In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in the Log table in Airflow Metadatase. Same happened when creating a Connection with a password field.
References
Link | Resource |
---|---|
https://lists.apache.org/thread.html/ree782a29d927b96bf0b39fb92e2f1f09ea3112a985f7a08ce93765ac%40%3Cusers.airflow.apache.org%3E | Mailing List Third Party Advisory |
Configurations
Information
Published : 2020-12-14 02:15
Updated : 2020-12-15 07:48
NVD link : CVE-2020-17511
Mitre link : CVE-2020-17511
JSON object : View
CWE
CWE-312
Cleartext Storage of Sensitive Information
Products Affected
apache
- airflow