CVE-2024-25142

CVE-2024-25142: Apache Airflow: Cache Control - Storage of Sensitive Data in Browser Cache

Vendor Apache Software Foundation
Product Apache Airflow
Weakness CWE-525
Published June 14, 2024
Last update March 20, 2025

CVSS base score

What the vulnerability does

Description

Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.  Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local cache of the browser. This issue affects Apache Airflow: before 2.9.2. Users are recommended to upgrade to version 2.9.2, which fixes the issue.

Key dates

Disclosure timeline

June 14, 2024 CVE published
March 20, 2025 Record updated