apache-airflow-task-sdk@1.1.3rc1 vulnerabilities

Python Task SDK for Apache Airflow DAG Authors

  • latest version

    1.1.6

  • latest non vulnerable version

  • first published

    10 months ago

  • latest version published

    6 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the apache-airflow-task-sdk package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Insertion of Sensitive Information into Log File

    apache-airflow-task-sdk is a The Apache Airflow Task SDK includes interfaces for Dag authors and Task execution logic for Python.

    Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File via the proxies and proxy fields in a Connection. An attacker can obtain sensitive proxy credentials if they are embedded in proxy URLs.

    How to fix Insertion of Sensitive Information into Log File?

    Upgrade apache-airflow-task-sdk to version 1.1.6rc1 or higher.

    [,1.1.6rc1)
    • M
    Improper Removal of Sensitive Information Before Storage or Transfer

    apache-airflow-task-sdk is a The Apache Airflow Task SDK includes interfaces for Dag authors and Task execution logic for Python.

    Affected versions of this package are vulnerable to Improper Removal of Sensitive Information Before Storage or Transfer via the serialization for rendered template fields when the length exceeds the configured maximum. An attacker can access sensitive information by viewing unmasked secrets displayed in the Rendered Templates UI.

    How to fix Improper Removal of Sensitive Information Before Storage or Transfer?

    Upgrade apache-airflow-task-sdk to version 1.1.6rc1 or higher.

    [,1.1.6rc1)
    • H
    Insertion of Sensitive Information Into Sent Data

    [1.0.0a2,1.1.4rc1)