-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| apache-airflow-providers-celery | pip | >= 3.3.0, < 3.4.1 | 3.4.1 |
| apache-airflow | pip | >= 1.10.0, < 2.7.0 | 2.7.0 |
The GitHub pull request #34954 shows a direct modification to the warning message in _get_async_backend() where connection URL logging was redacted. The vulnerability description explicitly mentions sensitive info exposure via these protocols' result backends, and the commit diff demonstrates the vulnerable logging pattern was present in this function before patching.
A Semantic Attack on Google Gemini - Read the Latest Research