HomeSecurityServers Apache Airflow: Why are thousands of credentials leaking?

Apache Airflow Servers: Why are thousands of credentials leaking?

While investigating a configuration error in Apache Airflow, researchers discovered multiple exposed instances on the web that were leaking sensitive information, including credentials, from well-known technology companies.

Apache Airflow is a popular open source workflow management platform for organizing and managing tasks.

This week, researchers Nicole Fishbein and Ryan Robinson from security firm Intezer revealed details about how they discovered misconfiguration bugs in Apache Airflow servers run by major tech companies.

See also: Microsoft Exchange Autodiscover: Bugs leak Windows credentials

Apache Airflow

The misconfiguration flaws led to the leakage of sensitive data, including thousands of credentials from popular platforms and services, such as Slack, PayPal, and Amazon Web Services (AWS), among others, the researchers claim:

“These unsecured instances expose sensitive information from companies in media, finance, manufacturing, information technology, biotechnology, e-commerce, healthcare, energy, cybersecurity, and transportation industries,” say Intezer researchers.

In various scenarios that researchers have analyzed, the most common reason for credential leakage observed on Airflow servers was insecure coding practices.

For example, the Intezer team discovered several instances of hard-coded passwords being generated within the Python DAG code:

“Passwords should not be hardcoded, and long image and dependency names should be used. You will not be protected when you use bad coding, even if you believe the application is up and running online,” Fishbein and Robinson warn.

See also: McDonald's leaks Monopoly VIP database credentials

In another case of misconfiguration, researchers saw Airflow servers with a publicly accessible configuration file:

“The configuration file (airflow.cfg) is created when Airflow is first started. It contains the Airflow configuration and can be changed,” the researchers state. The file contains secrets such as passwords and keys.

But, if the “expose_config” option in the file is accidentally set to “True”, the configuration becomes accessible to anyone via the web server, who can now see these secrets.

Apache Airflow Servers: Why are thousands of credentials leaking?

Research shows dangers of delayed repair

In addition to identifying improperly configured Airflow assets, the focus of this research was to draw attention to the risks that come from delaying software updates.

Intezer reports that the vast majority of these flaws were found on servers running Airflow v1.x from 2015, which are still used by organizations from different departments.

Airflow version 2 introduced several new security features, including a REST API that requires authentication for all operations. The newer version also does not store sensitive information in logs and forces the administrator to explicitly confirm configuration options, rather than following the defaults.

See also: Google: Removes popular Android apps that stole Facebook credentials

Exposing customer records and sensitive data due to security flaws resulting from delayed patching may violate data protection laws such as GDPR.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS