Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-54831

Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
26/09/2025
Última modificación:
04/11/2025

Descripción

*** Pendiente de traducción *** Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict access to sensitive connection fields to Connection Editing Users, effectively applying a "write-only" model for sensitive values.<br /> <br /> <br /> In Airflow 3.0.3, this model was unintentionally violated: sensitive connection information could be viewed by users with READ permissions through both the API and the UI. This behavior also bypassed the `AIRFLOW__CORE__HIDE_SENSITIVE_VAR_CONN_FIELDS` configuration option.<br /> <br /> <br /> This issue does not affect Airflow 2.x, where exposing sensitive information to connection editors was the intended and documented behavior.<br /> <br /> <br /> <br /> <br /> <br /> <br /> Users of Airflow 3.0.3 are advised to upgrade Airflow to &gt;=3.0.4.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:apache:airflow:3.0.3:-:*:*:*:*:*:*