apache-airflow-providers-google is vulnerable to Authorization Bypass
65
Medium Risk
The Google Cloud Secret Manager secrets backend accepts the caller's team name but drops it before resolving Connections and Variables, so every lookup runs against a team-agnostic secret name. In a multi-team deployment, a task or DAG in one team resolves another team's Connection or Variable and obtains its credentials in full. This breaks tenant isolation between teams that rely on the backend for scoped secrets. The fix builds and applies the team-scoped secret name so lookups stay within the caller's team.
You are affected if you are using a version that falls within the vulnerable range and you run Airflow in multi-team mode with the Google Cloud Secret Manager secrets backend.
apache-airflow-providers-google is vulnerable to Authorization Bypass in versions 0.0.1 - 22.2.2.
Upgrade the apache-airflow-providers-google library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant