Metrics
Affected Vendors & Products
Wed, 01 Oct 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:apache:airflow:3.0.3:-:*:*:*:*:*:* |
Mon, 29 Sep 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 29 Sep 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache airflow |
|
Vendors & Products |
Apache
Apache airflow |
Fri, 26 Sep 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Fri, 26 Sep 2025 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict access to sensitive connection fields to Connection Editing Users, effectively applying a "write-only" model for sensitive values. In Airflow 3.0.3, this model was unintentionally violated: sensitive connection information could be viewed by users with READ permissions through both the API and the UI. This behavior also bypassed the `AIRFLOW__CORE__HIDE_SENSITIVE_VAR_CONN_FIELDS` configuration option. This issue does not affect Airflow 2.x, where exposing sensitive information to connection editors was the intended and documented behavior. Users of Airflow 3.0.3 are advised to upgrade Airflow to >=3.0.4. | |
Title | Apache Airflow: Connection sensitive details exposed to users with READ permissions | |
Weaknesses | CWE-213 | |
References |
|

Status: PUBLISHED
Assigner: apache
Published: 2025-09-26T07:28:59.066Z
Updated: 2025-09-29T15:22:59.623Z
Reserved: 2025-07-30T12:43:41.056Z
Link: CVE-2025-54831

Updated: 2025-09-26T19:55:04.390Z

Status : Analyzed
Published: 2025-09-26T08:15:38.303
Modified: 2025-10-01T15:23:03.227
Link: CVE-2025-54831

No data.