apache-airflow-providers-hashicorp is vulnerable to Authorization Bypass Through User-Controlled Key
65
Medium Risk
The HashiCorp Vault secrets backend's team scoped lookup uses a team agnostic {base_path}/{key} path built from the caller supplied variable or connection key when that lookup finds no value. In a multi team deployment, a Dag author scoped to one team can supply a key that matches this shared fallback path and read a secret that belongs to a different team. The Execution API Variables route accepts this path shaped key directly from ordinary Dag code, so no elevated access is required to reach it. The fix removes the team agnostic fallback and uses an explicit, ordered list of configured base paths.
You are affected if you are using a version that falls within the vulnerable range and you run a multi team Airflow deployment with the HashiCorp Vault secrets backend and use_team_secrets_path enabled.
apache-airflow-providers-hashicorp is vulnerable to Authorization Bypass Through User-Controlled Key in versions 4.6.0 - 4.7.2.
Upgrade the apache-airflow-providers-hashicorp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.