U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2023-51702

Change History

New CVE Received by NIST 1/24/2024 8:15:08 AM

Action Type Old Value New Value
Added CWE

								
							
							
						
Apache Software Foundation CWE-312
Added CWE

								
							
							
						
Apache Software Foundation CWE-532
Added Description

								
							
							
						
Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any encryption. Additionally, if used with an Airflow version between 2.3.0 and 2.6.0, the configuration dictionary will be logged as plain text in the triggerer service without masking. This allows anyone with access to the metadata or triggerer log to obtain the configuration file and use it to access the Kubernetes cluster.

This behavior was changed in version 7.0.0, which stopped serializing the file contents and started providing the file path instead to read the contents into the trigger. Users are recommended to upgrade to version 7.0.0, which fixes this issue.
Added Reference

								
							
							
						
Apache Software Foundation https://github.com/apache/airflow/pull/29498 [No types assigned]
Added Reference

								
							
							
						
Apache Software Foundation https://github.com/apache/airflow/pull/30110 [No types assigned]
Added Reference

								
							
							
						
Apache Software Foundation https://github.com/apache/airflow/pull/36492 [No types assigned]
Added Reference

								
							
							
						
Apache Software Foundation https://lists.apache.org/thread/89x3q6lz5pykrkr1fkr04k4rfn9pvnv9 [No types assigned]