Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 01 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* |
Mon, 01 Jun 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 01 Jun 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache airflow |
|
| Vendors & Products |
Apache
Apache airflow |
|
| References |
|
Mon, 01 Jun 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read permission to retrieve secrets stored in a Connection's `extra` JSON blob under field names not present in the redaction allowlist (`DEFAULT_SENSITIVE_FIELDS`) — for example, official Slack-provider credential field names were returned in plaintext. Affects deployments that store credentials in Connection `extra` blobs and grant Connection-read access to multiple users. Users are advised to upgrade to `apache-airflow` 3.2.2 or later. As a defense-in-depth mitigation, deployment operators can store sensitive credential values in a secret-backend rather than inlined into the Connection's `extra` field. | |
| Title | Apache Airflow: Incomplete Redaction of Sensitive Fields in Connection Extra API Response | |
| Weaknesses | CWE-200 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-06-01T12:52:56.769Z
Reserved: 2026-05-10T21:43:28.304Z
Link: CVE-2026-45192
Updated: 2026-06-01T07:44:01.595Z
Status : Analyzed
Published: 2026-06-01T08:16:20.567
Modified: 2026-06-01T17:08:11.913
Link: CVE-2026-45192
No data.
OpenCVE Enrichment
Updated: 2026-06-01T14:45:26Z