Skip to content
Apache AirflowPYSEC-2024-182

Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability allows DAG authors to unintentionally or intentionally log sensitive configuration variables. Unauthorized users could access these logs, potentially exp

High7.5CVE-2024-45784 · Published Nov 15, 2024 · updated Jul 7, 2026

Source advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.10.32.10.3

Changes since it was listed

DateChange
Sep 24Severity: Unrated to High
Details and references

Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability allows DAG authors to unintentionally or intentionally log sensitive configuration variables. Unauthorized users could access these logs, potentially exposing critical data that could be exploited to compromise the security of the Airflow deployment. In version 2.10.3, secrets are now masked in task logs to prevent sensitive configuration variables from being exposed in the logging output. Users should upgrade to Airflow 2.10.3 or the latest version to eliminate this vulnerability. If you suspect that DAG authors could have logged the secret values to the logs and that your logs are not additionally protected, it is also recommended that you update those secrets.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
NVD
Also known as
BIT-airflow-2024-45784, CVE-2024-45784, GHSA-46c3-5xc5-wwhv, PYSEC-2026-1112

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Nov 82024Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data
CVE-2024-50378Low6.5fixed in 2.10.3
Sep 72024Apache Airflow vulnerable to Execution with Unnecessary Privileges
CVE-2024-45034High8.8fixed in 2.10.1
Sep 72024Apache Airflow vulnerable to Improper Encoding or Escaping of Output
CVE-2024-45498High8.8fixed in 2.10.1
Aug 212024Apache Airflow Cross-site Scripting Vulnerability
CVE-2024-41937Medium6.1fixed in 2.10.0
Aug 52024Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB.
CVE-2024-42447Critical9.8no fix yet
Jul 172024Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler
CVE-2024-39877High8.8fixed in 2.9.3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.