Bug 2238619 (CVE-2023-40712)

Summary: CVE-2023-40712 Apache Airflow: Secrets can be unmasked in the "Rendered Template"
Product: [Other] Security Response Reporter: Marco Benatto <mbenatto>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-09-12 20:49:30 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2238620    
Bug Blocks:    

Description Marco Benatto 2023-09-12 20:49:01 UTC
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be masked in the UI.

Users are strongly advised to upgrade to version 2.7.1 or later which has removed the vulnerability.

https://github.com/apache/airflow/pull/33516
https://github.com/apache/airflow/pull/33512
https://lists.apache.org/thread/jw1yv4lt6hpowqbb0x4o3tdp0jhx2bts

Comment 1 Marco Benatto 2023-09-12 20:49:16 UTC
Created golang-cloud-google tracking bugs for this issue:

Affects: fedora-all [bug 2238620]