apache-airflow-providers-odbc@3.3.0 vulnerabilities

Provider package apache-airflow-providers-odbc for Apache Airflow

  • latest version

    4.9.0

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    14 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the apache-airflow-providers-odbc package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Arbitrary Argument Injection

    apache-airflow-providers-odbc is a Provider for Apache Airflow. Implements apache-airflow-providers-odbc package

    Affected versions of this package are vulnerable to Arbitrary Argument Injection due to controllable ODBC driver parameters that allow the loading of arbitrary dynamic-link libraries.

    How to fix Arbitrary Argument Injection?

    Upgrade apache-airflow-providers-odbc to version 4.0.0 or higher.

    [,4.0.0)
    • M
    Improper Input Validation

    apache-airflow-providers-odbc is a Provider for Apache Airflow. Implements apache-airflow-providers-odbc package

    Affected versions of this package are vulnerable to Improper Input Validation. This vulnerability requires DAG code to use the get_sqlalchemy_connection method and someone with access to connection resources specifically updating the connection to exploit it.

    How to fix Improper Input Validation?

    Upgrade apache-airflow-providers-odbc to version 4.0.0 or higher.

    [,4.0.0)