Skip to content
Apache AirflowGHSA-j857-2pwm-jjmm

Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data

Low6.5CVE-2024-50378 · Published Nov 8, 2024 · updated Sep 10, 2026

Airflow versions before 2.10.3 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive variables were set via airflow CLI, values of those variables appeared in the audit log and were stored unencrypted in the Airflow database. While this risk is limited to users with audit log access, it is recommended to upgrade to Airflow 2.10.3 or a later version, which addresses this issue. Users who previously used the CLI to set secret variables should manually delete entries with those variables from the log table.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.10.32.10.3
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-201
Also known as
BIT-airflow-2024-50378, CVE-2024-50378, PYSEC-2026-1134

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow versions before 2.10.3 contain a vulnerability
High7.5Nov 15, 2024
Apache Airflow vulnerable to Execution with Unnecessary Privileges
High8.8Sep 7, 2024
Apache Airflow vulnerable to Improper Encoding or Escaping of Output
High8.8Sep 7, 2024
Apache Airflow Cross-site Scripting Vulnerability
Medium6.1Aug 21, 2024
Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB
Critical9.8Aug 5, 2024
Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler
High8.8Jul 17, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.