Executive brief
Apache Airflow is a widely-used workflow orchestration platform. A vulnerability in versions 2.7.0–2.8.4 allows authenticated users to view sensitive provider configuration (such as database credentials for the Celery provider) through the web UI's configuration page, even when configured to display only non-sensitive settings. An attacker with valid login credentials could expose secrets and potentially compromise integrated systems.
Technical details
A CWE-200 information disclosure vulnerability exists in Apache Airflow's configuration UI. When the "webserver.expose_config" setting is set to "non-sensitive-only", the web interface should filter out sensitive configuration values before display. However, the implementation fails to properly redact sensitive provider configurations in versions 2.7.0 through 2.8.4, allowing authenticated users to view secrets intended to be hidden. The vulnerability is specific to the web UI configuration page and differs from a related API disclosure (CVE-2023-46288). Exploitation requires valid Airflow user credentials and network access to the web interface. The issue has been resolved in Airflow 2.9.0 and later; temporary mitigation involves setting "expose_config" to False.
Affected products
- Apache Airflow 2.7.0 through 2.8.4
Timeline
- 2024-04-18: disclosed
- 2024-04-06: patched: Fix merged in PR #38795; available in Airflow 2.9.0