Intel

AIKIDO-2024-10203

kedro-datasets is vulnerable to Exposure of Sensitive Information

Exposure of Sensitive Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Aug 2, 2024

30

Low Risk

This Affects:

pythonkedro-datasets
3.0.0 - 4.0.0
Fixed in 4.1.0
Are you affected? Scan for Free

TL;DR

Affected versions of the package expose sensitive information by not masking credentials in the ibis dataset when printed.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

kedro-datasets is vulnerable to Exposure of Sensitive Information in versions 3.0.0 - 4.0.0.

How to fix this

Upgrade the kedro-datasets library to the patch version.