{"id":"BIT-airflow-2024-31869","summary":"Apache Airflow: Sensitive configuration for providers displayed when \"non-sensitive-only\" config used","details":"Airflow versions 2.7.0 through 2.8.4 have a vulnerability that allows an authenticated user to see sensitive provider configuration via the \"configuration\" UI page when \"non-sensitive-only\" was set as \"webserver.expose_config\" configuration (The celery provider is the only community provider currently that has sensitive configurations). You should migrate to Airflow 2.9 or change your \"expose_config\" configuration to False as a workaround. This is similar, but different to  CVE-2023-46288 https://github.com/advisories/GHSA-9qqg-mh7c-chfq  which concerned API, not UI configuration page.","aliases":["CVE-2024-31869","GHSA-2522-mrjc-m688","PYSEC-2026-1128"],"modified":"2026-09-10T16:00:08.191640840Z","published":"2024-04-20T07:16:43.969Z","database_specific":{"cpes":["cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*","cpe:2.3:a:apache:airflow:*:*:*:*:*:python:*:*"],"severity":"Medium"},"references":[{"type":"FIX","url":"https://github.com/apache/airflow/pull/38795"},{"type":"DISCUSSION","url":"https://lists.apache.org/thread/pz6vg7wcjk901rmsgt86h76g6kfcgtk3"},{"type":"DISCUSSION","url":"http://www.openwall.com/lists/oss-security/2024/04/17/10"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-31869"}],"affected":[{"package":{"name":"airflow","ecosystem":"Bitnami","purl":"pkg:bitnami/airflow"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.7.0"},{"fixed":"2.9.0"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/airflow/BIT-airflow-2024-31869.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}],"schema_version":"1.9.0"}