apache-airflow-providers-teradata@3.2.1rc1

Provider package apache-airflow-providers-teradata for Apache Airflow

  • latest version

    3.7.0

  • latest non vulnerable version

  • first published

    5 years ago

  • latest version published

    6 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the apache-airflow-providers-teradata package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Insertion of Sensitive Information into Log File

    apache-airflow-providers-teradata is a Provider package apache-airflow-providers-teradata for Apache Airflow

    Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File via the execute method in azure_blob_to_teradata.py and s3_to_teradata.py, when no teradata_authorization_name is configured and the object store is private. Both AzureBlobStorageToTeradataOperator and S3ToTeradataOperator embed object store credentials directly inside the CREATE TABLE SQL statement, and DbApiHook logs every statement it executes, causing the plaintext credentials to be written to the Airflow task log on each run. For S3ToTeradataOperator, credentials obtained via s3_hook.get_credentials() under an instance profile or IRSA are runtime AWS credentials that were never registered with Airflow's secrets masker, meaning the STS session token is unmasked even when an AWS connection is configured. Additionally, Teradata records the statement in its own query logs (DBQL) and monitoring views, which Airflow cannot redact, exposing the credentials to anyone with access to those logs.

    Note: This is only exploitable when teradata_authorization_name is not set and the object store bucket is private.

    How to fix Insertion of Sensitive Information into Log File?

    Upgrade apache-airflow-providers-teradata to version 3.7.0rc1 or higher.

    [0,3.7.0rc1)
    • M
    SQL Injection

    apache-airflow-providers-teradata is a Provider package apache-airflow-providers-teradata for Apache Airflow

    Affected versions of this package are vulnerable to SQL Injection in the Teradata compute-cluster example DAG, where user-settable Params are not properly constrained, allowing an attacker to supply arbitrary values through those parameters. This lack of validation can lead to unintended behavior or abuse of the DAG execution context.

    How to fix SQL Injection?

    Upgrade apache-airflow-providers-teradata to version 3.7.0rc1 or higher.

    [0,3.7.0rc1)