CVE-2020-17511
EUVD-2020-004314.12.2020, 10:15
In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in the Log table in Airflow Metadatase. Same happened when creating a Connection with a password field.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | airflow | 𝑥 < 1.10.13 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration