CVE-2025-54831
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/09/2025
Last modified:
04/11/2025
Description
Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict access to sensitive connection fields to Connection Editing Users, effectively applying a "write-only" model for sensitive values.<br />
<br />
<br />
In Airflow 3.0.3, this model was unintentionally violated: sensitive connection information could be viewed by users with READ permissions through both the API and the UI. This behavior also bypassed the `AIRFLOW__CORE__HIDE_SENSITIVE_VAR_CONN_FIELDS` configuration option.<br />
<br />
<br />
This issue does not affect Airflow 2.x, where exposing sensitive information to connection editors was the intended and documented behavior.<br />
<br />
<br />
<br />
<br />
<br />
<br />
Users of Airflow 3.0.3 are advised to upgrade Airflow to >=3.0.4.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apache:airflow:3.0.3:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



