CVE-2025-54831
Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
26/09/2025
Última modificación:
04/11/2025
Descripción
*** Pendiente de traducción *** Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict access to sensitive connection fields to Connection Editing Users, effectively applying a "write-only" model for sensitive values.<br />
<br />
<br />
In Airflow 3.0.3, this model was unintentionally violated: sensitive connection information could be viewed by users with READ permissions through both the API and the UI. This behavior also bypassed the `AIRFLOW__CORE__HIDE_SENSITIVE_VAR_CONN_FIELDS` configuration option.<br />
<br />
<br />
This issue does not affect Airflow 2.x, where exposing sensitive information to connection editors was the intended and documented behavior.<br />
<br />
<br />
<br />
<br />
<br />
<br />
Users of Airflow 3.0.3 are advised to upgrade Airflow to >=3.0.4.
Impacto
Puntuación base 3.x
6.50
Gravedad 3.x
MEDIA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:apache:airflow:3.0.3:-:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página



