CVE-2023-51702

Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service

Description

Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any encryption. Additionally, if used with an Airflow version between 2.3.0 and 2.6.0, the configuration dictionary will be logged as plain text in the triggerer service without masking. This allows anyone with access to the metadata or triggerer log to obtain the configuration file and use it to access the Kubernetes cluster. This behavior was changed in version 7.0.0, which stopped serializing the file contents and started providing the file path instead to read the contents into the trigger. Users are recommended to upgrade to version 7.0.0, which fixes this issue.

Category

6.5
CVSS
Severity: Medium
CVSS 3.1 •
EPSS 0.05%
Vendor Advisory apache.org
Affected: Apache Software Foundation Apache Airflow CNCF Kubernetes provider
Affected: Apache Software Foundation Apache Airflow
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2023-51702?
CVE-2023-51702 has been scored as a medium severity vulnerability.
How to fix CVE-2023-51702?
To fix CVE-2023-51702, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2023-51702 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2023-51702 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2023-51702?
CVE-2023-51702 affects Apache Software Foundation Apache Airflow CNCF Kubernetes provider, Apache Software Foundation Apache Airflow.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.