High severity7.5NVD Advisory· Published Nov 14, 2022· Updated Jun 17, 2026
CVE-2022-27949
CVE-2022-27949
Description
A vulnerability in UI of Apache Airflow allows an attacker to view unmasked secrets in rendered template values for tasks which were not executed (for example when they were depending on past and previous instances of the task failed). This issue affects Apache Airflow prior to 2.3.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-airflowPyPI | < 2.3.1 | 2.3.1 |
Affected products
4- osv-coords2 versions
< 2.3.1+ 1 more
- (no CPE)range: < 2.3.1
- (no CPE)range: < 2.3.1
Patches
Vulnerability mechanics
References
8- github.com/apache/airflow/pull/22754nvdPatchThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2022/11/14/3nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-fvw2-2pf7-77vwghsaADVISORY
- lists.apache.org/thread/n38oc5obb48600fsvnbopxcs0jpbp65pnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-27949ghsaADVISORY
- github.com/apache/airflow/commit/09be0c5c7e847dda1d0be5776f8d5e327ff2281aghsaWEB
- github.com/apache/airflow/commit/1cbb0ad26dd17f218c6ab1c2ae59b262c443a443ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2022-42981.yamlghsaWEB
News mentions
0No linked articles in our index yet.