apache-airflow-providers-microsoft-azure is vulnerable to Authorization Bypass
63
Medium Risk
The Azure Key Vault secrets backend supports team-scoped secret lookups for multi-team deployments, probing a team-scoped name before falling back to a team-agnostic name. A guard meant to reject identifiers that spell another team's namespace never runs when a team scope is supplied, so a team-scoped lookup that misses falls through and resolves the named secret. A caller authorized for one team can supply a secret identifier that spells out another team's namespace and read that team's secret value. The fix refuses the team-agnostic fall-through for any identifier that spells a team-scoped name, applies the same ambiguous-identifier refusal to the configuration lookup, and gates the behavior on multi-team mode.
You are affected if you are using a version that falls within the vulnerable range and you have enabled multi-team mode and use the Azure Key Vault secrets backend with team-scoped secret names.
apache-airflow-providers-microsoft-azure is vulnerable to Authorization Bypass in versions 13.2.0 - 14.0.0.
Upgrade the apache-airflow-providers-microsoft-azure library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant