Логотип exploitDog
bind:CVE-2025-65995
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-65995

Количество 3

Количество 3

nvd логотип

CVE-2025-65995

около 2 месяцев назад

When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operators. If those kwargs contained sensitive values (such as secrets), they might be exposed in the UI tracebacks to authenticated users who had permission to view that DAG.  The issue has been fixed in Airflow 3.1.4 and 2.11.1, and users are strongly advised to upgrade to prevent potential disclosure of sensitive information.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-65995

около 2 месяцев назад

When a DAG failed during parsing, Airflow\u2019s error-reporting in th ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-gfw7-2v73-69wg

около 2 месяцев назад

Apache Airflow error reporting may expose full kwargs

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-65995

When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operators. If those kwargs contained sensitive values (such as secrets), they might be exposed in the UI tracebacks to authenticated users who had permission to view that DAG.  The issue has been fixed in Airflow 3.1.4 and 2.11.1, and users are strongly advised to upgrade to prevent potential disclosure of sensitive information.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-65995

When a DAG failed during parsing, Airflow\u2019s error-reporting in th ...

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-gfw7-2v73-69wg

Apache Airflow error reporting may expose full kwargs

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу