CVE-2024-25142 Details
Description
Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow. Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local cache of the browser. This issue affects Apache Airflow: before 2.9.2. Users are recommended to upgrade to version 2.9.2, which fixes the issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 14, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/apache/airflow/pull/39550 | CVE | Patch |
| https://lists.apache.org/thread/cg1j28lk0fhzthk0of1g7vy7p2n1j7nr | CVE | Mailing ListVendor Advisory |
| http://www.openwall.com/lists/oss-security/2024/06/13/1 | CVE | Mailing ListThird Party Advisory |
| https://github.com/apache/airflow/pull/39550 | [email protected] | Patch |
| https://lists.apache.org/thread/cg1j28lk0fhzthk0of1g7vy7p2n1j7nr | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
| CWE-525 | Use of Web Browser Cache Containing Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache airflow | < 2.9.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 20, 2025 | CVE Modified | CISA-ADP |
| Dec 11, 2024 | Initial Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jun 14, 2024 | New CVE Received | [email protected] |