dbt-databricks is vulnerable to Improper Input Validation
20
Low Risk
Affected versions of this package have improper input validation. Query tag values were not validated. Special characters like backslashes, commas, and colons remained unescaped. Values longer than 128 characters could be processed without truncation, resulting in invalid query tags. An attacker could inject crafted query tag values using these characters to manipulate query parsing. It might lead to data corruption, security breaches, or system errors.
You are affected if you are using a version that falls within the vulnerable range.
dbt-databricks is vulnerable to Improper Input Validation in versions 1.0.0 - 1.11.2.
Upgrade the dbt-databricks library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant