CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Apache 2Airflow Providers Amazon Apache Airflow Providers AmazonJul 24, 2026 May 19, 2026 N/A· v4 5.3 MEDIUM· v3 N/A· v2 In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0, the team-scoping logic could resolve a `conn_id` containing a `/` (e.g. `"my_team/conn"`) to the s...Show more |
1Apache 2Airflow Providers Amazon Apache Airflow Providers AmazonJul 2, 2026 Mar 9, 2026 N/A· v4 5.4 MEDIUM· v3 N/A· v2 In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially di...Show more |
1Apache 1Apache Airflow Providers Amazon Jun 17, 2026 Feb 24, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Generation of Error Message Containing Sensitive Information vulnerability in the Apache Airflow AWS Provider.
This issue affects Apache Airflow AWS Provider versions before 7.2.1.
|