Junglewise Threat Intelligence
CVE-2023-51702: PYSEC-2026-2350 - Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged a
CVE-2023-51702 · Severity: low · CVSS 3.1 · Published 2026-07-13
Technologies: apache-airflow-providers-cncf-kubernetes (PyPI), apache-airflow (PyPI). Vendors: PyPI.
Executive brief
Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service
Affected products
- PyPI apache-airflow-providers-cncf-kubernetes
- PyPI apache-airflow