CVE-2025-27555
Last modified
CVE-2025-27555 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive connection parameters were set via airflow CLI, values of those variables appeared in the audit log and were stored unencrypted in the Airflow database. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive connection parameters were set via airflow CLI, values of those variables appeared in the audit log and were stored unencrypted in the Airflow database. While this risk is limited to users with audit log access, it is recommended to upgrade to Airflow 2.11.1 or a later version, which addresses this issue. Users who previously used the CLI to set connections should manually delete entries with those connection sensitive values from the log table. This is similar but not the same issue as CVE-2024-50378
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Airflow | < 2.11.1 |
References
- https://github.com/apache/airflow/pull/61882Issue Tracking
- https://lists.apache.org/thread/nxovkp319jo8vg498gql1yswtb2frbkwMailing List, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-27555?
How severe is CVE-2025-27555?
How do I fix CVE-2025-27555?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-2755A vulnerability was found in Open Asset Import Library Assim…8.8
- CVE-2025-27550IBM Jazz Reporting Service could allow an authenticated user…3.5
- CVE-2025-27551DBIx::Class::EncodedColumn use the rand() function, which is…4
- CVE-2025-27552DBIx::Class::EncodedColumn use the rand() function, which is…4
- CVE-2025-27553Relative Path Traversal vulnerability in Apache Commons VFS …7.5
- CVE-2025-27554ToDesktop before 2024-10-03, as used by Cursor before 2024-1…9.9
- CVE-2025-27556An issue was discovered in Django 5.1 before 5.1.8 and 5.0 b…7.5
- CVE-2025-27558IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks agai…9.1
- CVE-2025-27559Incorrect default permissions for some AI Playground softwar…6.7
- CVE-2025-2756A vulnerability classified as critical has been found in Ope…8.8
- CVE-2025-27560Loop with unreachable exit condition ('infinite loop') for s…6.7
- CVE-2025-27561Unauthenticated attackers can rename "rooms" of arbitrary us…6.9
Are you affected by CVE-2025-27555?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
