redshift-connector@2.1.6 vulnerabilities

Redshift interface library

  • latest version

    2.1.7

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    13 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the redshift-connector package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Improper Certificate Validation

    redshift-connector is a Redshift interface library

    Affected versions of this package are vulnerable to Improper Certificate Validation when using the BrowserAzureOAuth2CredentialsProvider plugin. An attacker can intercept token exchange communication and retrieve an access token by leveraging the default configuration, which allows for insecure connections by skipping the SSL certificate validation for the Identity Provider.

    How to fix Improper Certificate Validation?

    Upgrade redshift-connector to version 2.1.7 or higher.

    [2.0.872,2.1.7)