Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow. 

Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local cache of the browser.

This issue affects Apache Airflow: before 2.9.2.

Users are recommended to upgrade to version 2.9.2, which fixes the issue.

Subscriptions

Vendors Products
Airflow Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-0012 Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.  Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local cache of the browser. This issue affects Apache Airflow: before 2.9.2. Users are recommended to upgrade to version 2.9.2, which fixes the issue.
Github GHSA Github GHSA GHSA-9xpj-62mm-24h2 Apache Airflow does not return the "Cache-Control" header for dynamic content
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 20 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Dec 2024 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache airflow
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache airflow
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Fri, 13 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-03-20T19:18:38.244Z

Reserved: 2024-02-06T09:11:20.044Z

Link: CVE-2024-25142

cve-icon Vulnrichment

Updated: 2024-09-13T16:03:08.456Z

cve-icon NVD

Status : Modified

Published: 2024-06-14T09:15:09.103

Modified: 2025-03-20T20:15:31.320

Link: CVE-2024-25142

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses