apache-airflow-providers-yandex is vulnerable to Insecure Direct Object Reference (IDOR)
58
Medium Risk
The Yandex Cloud Lockbox secrets backend resolves a team-scoped Connection or Variable ID through a team-agnostic fallback lookup whenever the team-scoped lookup misses. The guard meant to block that path only checks whether team context is absent, so it never runs when a caller from one team supplies an ID that names another team's namespace and retrieves that team's secret credentials in full. The fix refuses any Connection, Variable, or Config lookup whose ID names a team namespace before either lookup runs.
You are affected if you are using a version that falls within the vulnerable range and run Apache Airflow in multi-team mode with the Yandex Cloud Lockbox secrets backend for Connections or Variables.
apache-airflow-providers-yandex is vulnerable to Insecure Direct Object Reference (IDOR) in versions 4.5.0 - 4.5.0.
Upgrade the apache-airflow-providers-yandex library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant