CVE-2026-32690
נמוכה 3.7
תיאור (מקור, אנגלית)
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked. If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise please upgrade to Apache Airflow 3.2.0 that has the fix implemented
מדדים
- CVSS 3.1
-
3.7 (LOW)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-28/7/2026
- CWE
- CWE-668
מוצרים מושפעים
apache: airflow
קישורים
- https://lists.apache.org/thread/7rnzxofntcznqxnhsmjvvlvygwph7rn5 Mailing ListVendor Advisory
- https://github.com/apache/airflow/pull/63480 Issue Tracking
- http://www.openwall.com/lists/oss-security/2026/04/17/6 Mailing ListThird Party Advisory