漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic options
Vulnerability Description
The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options whose option names were not in `sensitive_config_values`, so the masker did not redact them. An authenticated UI/API user with Config read permission could retrieve plaintext secrets-backend credentials (Vault `role_id` / `secret_id`, etc.) from the Config API output. Affects deployments that configure secrets backends via per-key environment overrides. Users are advised to upgrade to `apache-airflow` 3.3.0 or later.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
Apache Airflow 信息泄露漏洞
Vulnerability Description
Apache Software Foundation Apache Airflow是Apache Software Foundation基金会的开源工作流调度与数据管道编排平台。 Apache Airflow 3.3.0之前版本存在信息泄露漏洞,该漏洞源于Config API将每个密钥的后端覆盖公开为合成配置选项,且未列入敏感值列表导致掩码器未隐去这些选项,经过身份验证且具有配置读取权限的UI/API用户可能从Config API输出中检索到明文的后端凭据。
CVSS Information
N/A
Vulnerability Type
N/A