apache-airflow is vulnerable to Authorization Bypass
50
Medium Risk
The environment-variable secrets backend resolves a team-scoped Connection from the wrong team's scope. The guard meant to prevent this runs only when no team scope is supplied and cannot match team names containing an underscore, so the lookup falls through to an unconditional global read. In multi-team mode a user of one team can make the connection-test endpoint resolve another team's Connection and authenticate outward with its credentials. The fix applies the team-scope guard consistently.
You are affected if you are using a version that falls within the vulnerable range and you run multi-team mode with the environment-variable secrets backend and enable connection testing.
apache-airflow is vulnerable to Authorization Bypass in versions 3.2.0 - 3.3.0.
Upgrade the apache-airflow library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant