icon

We found results for “

CVE-2024-25142

Good to know:

icon
icon

Date: June 14, 2024

Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.  Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local cache of the browser. This issue affects Apache Airflow: before 2.9.2. Users are recommended to upgrade to version 2.9.2, which fixes the issue.

Language: Python

Severity Score

Severity Score

Weakness Type (CWE)

Use of Web Browser Cache Containing Sensitive Information

CWE-525

Top Fix

icon

Upgrade Version

Upgrade to version apache-airflow - 2.9.2

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): LOCAL
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us