Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authent…
中危 CVSS 6.5
摘要
Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configuration-read access — with no prior access to the secret — could read a team-scoped Celery broker URL, including its embedded credentials, in cleartext, while the equivalent global option was correctly masked. The secrets masker matched only base section and option n…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/apache/airflow/pull/70755 Issue Tracking
- https://lists.apache.org/thread/kykn94kjf0tntx4wywtvjowh5bzdgf38 Mailing List
- https://www.cve.org/CVERecord?id=CVE-2026-48828 Not Applicable
- https://www.cve.org/CVERecord?id=CVE-2026-48892 Not Applicable
时间线
- nvd_ingest NVD