#VU85793 Inclusion of Sensitive Information in Log Files in Apache Airflow and Apache Airflow CNCF Kubernetes provider - CVE-2023-51702
Published: January 25, 2024
Apache Airflow
Apache Airflow CNCF Kubernetes provider
Apache Foundation
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to Airflow worker serializes Kubernetes configuration file for authentication as a dictionary and sends it to the triggerer by storing it in metadata without any encryption. A local user can read the log files and gain access to sensitive data.