NIXPKGS-2026-1194
GitHub issue
published 2 months, 1 week ago
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked. If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise please upgrade to Apache Airflow 3.2.0 that has the fix implemented
References
Affected products
apache-airflow
- <3.2.0
Matching in nixpkgs
pkgs.apache-airflow
Platform to programmatically author, schedule and monitor workflows
Package maintainers
-
@taranarmo Sergey Volkov <taranarmo@gmail.com>