CVE-2020-17511
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 2.6%
exploitation probability
2.6%top 15% of all CVEs
observed exploitation
nono source reports it
In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in the Log table in Airflow Metadatase. Same happened when creating a Connection with a password field.
Affected products
Apache Software Foundation · Apache Airflow