apache-airflow-providers-apache-kafka is vulnerable to Unsafe Reflection
88
High Risk
The Apache Kafka provider resolves dotted-path strings found in consumed message data by importing and calling the object they name. Message content that an external producer controls can point that dotted path at an arbitrary importable callable. Consuming such a message causes Airflow to import and invoke code the message itself selected. The fix restricts dotted-path resolution to a safe, allow-listed set of callables.
You are affected if you are using a version that falls within the vulnerable range and consume Kafka messages whose content is not fully trusted.
apache-airflow-providers-apache-kafka is vulnerable to Unsafe Reflection in versions 1.15.0 - 1.16.0.
Upgrade the apache-airflow-providers-apache-kafka library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.