Vulnerabilities > Apache > Airflow Cncf Kubernetes > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-01-24 CVE-2023-51702 Cleartext Storage of Sensitive Information vulnerability in Apache Airflow and Airflow Cncf Kubernetes
Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any encryption.
network
low complexity
apache CWE-312
6.5