Executive brief
Apache Airflow, a platform used to schedule and monitor workflows, contains a flaw that exposes sensitive connection credentials to unauthorized users. In version 3.0.3, users who should only have basic 'read' access can view sensitive information like passwords and tokens through the user interface and API. This could allow an internal user to gain unauthorized access to external databases or services integrated with the Airflow environment.
Technical details
An information disclosure vulnerability exists in Apache Airflow 3.0.3 due to an improper implementation of the 'write-only' model for sensitive connection fields. While Airflow 3 intended to restrict sensitive data to users with edit privileges, a regression in version 3.0.3 allows users with only READ permissions to access these fields through both the REST API and the web UI. This flaw also bypasses the AIRFLOW__CORE__HIDE_SENSITIVE_VAR_CONN_FIELDS configuration setting. Attackers with network access to the Airflow instance and valid read-only credentials can extract sensitive connection details. The issue is resolved in version 3.0.4.
Affected products
- Apache Airflow 3.0.3
Timeline
- 2025-09-25: disclosed: Initial disclosure on oss-security mailing list
- 2025-09-26: advisory: GitHub Advisory and NVD record published
- 2025-09-26: patched: Version 3.0.4 released to address the issue