apache-airflow-providers-google is vulnerable to Path Traversal
81
High Risk
The Google provider operators GCSToSFTPOperator and GCSTimeSpanFileTransformOperator join Google Cloud Storage object names onto a destination filesystem path without normalizing them or checking containment. An object name that contains .. segments resolves outside the configured destination when a DAG run downloads it. A principal with write access to the source bucket can overwrite arbitrary files on the SFTP server or the Airflow worker host, which can lead to host compromise. The fix normalizes object names and rejects paths that escape the configured base directory.
You are affected if you are using a version that falls within the vulnerable range and you ingest from a Google Cloud Storage bucket writable by an untrusted principal using GCSToSFTPOperator or GCSTimeSpanFileTransformOperator.
apache-airflow-providers-google is vulnerable to Path Traversal in versions 0.0.1 - 22.2.0.
Upgrade the apache-airflow-providers-google library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant