#VU67552 Race condition in Apache Airflow - CVE-2022-38170
Published: September 21, 2022
Apache Airflow
Apache Foundation
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to an insecure umask that was configured for numerous Airflow components when running with the `--daemon` flag. A local user can exploit the race condition to allow local users to expose arbitrary file contents via the web server.