CVE-2024-25142
Apache Airflow: Cache Control - Storage of Sensitive Data in Browser Cache
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.
Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local cache of the browser.
This issue affects Apache Airflow: before 2.9.2.
Users are recommended to upgrade to version 2.9.2, which fixes the issue.
Uso de la vulnerabilidad de caché del navegador web que contiene información confidencial en Apache Airflow. Airflow no devolvió el encabezado "Cache-Control" para contenido dinámico, lo que en el caso de algunos navegadores podría resultar en el almacenamiento de datos confidenciales en la caché local del navegador. Este problema afecta a Apache Airflow: antes de 2.9.2. Se recomienda a los usuarios actualizar a la versión 2.9.2, que soluciona el problema.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-02-06 CVE Reserved
- 2024-06-14 CVE Published
- 2024-06-15 EPSS Updated
- 2024-09-13 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-525: Use of Web Browser Cache Containing Sensitive Information
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/apache/airflow/pull/39550 | 2024-06-17 |
URL | Date | SRC |
---|---|---|
https://lists.apache.org/thread/cg1j28lk0fhzthk0of1g7vy7p2n1j7nr | 2024-06-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Software Foundation Search vendor "Apache Software Foundation" | Apache Airflow Search vendor "Apache Software Foundation" for product "Apache Airflow" | < 2.9.2 Search vendor "Apache Software Foundation" for product "Apache Airflow" and version " < 2.9.2" | en |
Affected
|