Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability allows DAG authors to unintentionally or intentionally log sensitive configuration variables. Unauthorized users could access these logs, potentially exp
High7.5CVE-2024-45784 · Published Nov 15, 2024 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | < 2.10.3 | 2.10.3 |
Changes since it was listed
| Date | Change |
|---|---|
| Sep 24 | Severity: Unrated to High |
Details and references
Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability allows DAG authors to unintentionally or intentionally log sensitive configuration variables. Unauthorized users could access these logs, potentially exposing critical data that could be exploited to compromise the security of the Airflow deployment. In version 2.10.3, secrets are now masked in task logs to prevent sensitive configuration variables from being exposed in the logging output. Users should upgrade to Airflow 2.10.3 or the latest version to eliminate this vulnerability. If you suspect that DAG authors could have logged the secret values to the logs and that your logs are not additionally protected, it is also recommended that you update those secrets.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- NVD
- Also known as
- BIT-airflow-2024-45784, CVE-2024-45784, GHSA-46c3-5xc5-wwhv, PYSEC-2026-1112
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Nov 82024 | Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data CVE-2024-50378Low6.5fixed in 2.10.3 | Low6.5 | 2.10.3 |
| Sep 72024 | Apache Airflow vulnerable to Execution with Unnecessary Privileges CVE-2024-45034High8.8fixed in 2.10.1 | High8.8 | 2.10.1 |
| Sep 72024 | Apache Airflow vulnerable to Improper Encoding or Escaping of Output CVE-2024-45498High8.8fixed in 2.10.1 | High8.8 | 2.10.1 |
| Aug 212024 | Apache Airflow Cross-site Scripting Vulnerability CVE-2024-41937Medium6.1fixed in 2.10.0 | Medium6.1 | 2.10.0 |
| Aug 52024 | Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. CVE-2024-42447Critical9.8no fix yet | Critical9.8 | No fix yet |
| Jul 172024 | Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler CVE-2024-39877High8.8fixed in 2.9.3 | High8.8 | 2.9.3 |