0.11.0
1 years ago
2 days ago
Known vulnerabilities in the apache-airflow-providers-keycloak package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
apache-airflow-providers-keycloak is a Provider package apache-airflow-providers-keycloak for Apache Airflow Affected versions of this package are vulnerable to Reliance on Cookies without Validation and Integrity Checking via How to fix Reliance on Cookies without Validation and Integrity Checking? Upgrade | [,0.10.0rc1) |
apache-airflow-providers-keycloak is a Provider package apache-airflow-providers-keycloak for Apache Airflow Affected versions of this package are vulnerable to Incorrect Authorization in the unauthenticated Note: This is only exploitable if the Keycloak realm is shared with other confidential clients and the attacker possesses valid credentials for one of those clients. How to fix Incorrect Authorization? Upgrade | [,0.10.0rc1) |