GHSA-qmrf-jrpr-rjx6

Suggest an improvement
Source
https://github.com/advisories/GHSA-qmrf-jrpr-rjx6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-qmrf-jrpr-rjx6/GHSA-qmrf-jrpr-rjx6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qmrf-jrpr-rjx6
Aliases
Published
2026-08-10T21:32:02Z
Modified
2026-10-02T23:40:51Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Apache Airflow Yandex Lockbox backend allows cross-team secret disclosure
Details

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-yandex 4.5.1 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace.

Database specific
{
    "cwe_ids":  [
        "CWE-639"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-02T23:11:39Z",
    "nvd_published_at":  "2026-08-10T19:17:30Z",
    "severity":  "MODERATE"
}
References

Affected packages

PyPI / apache-airflow-providers-yandex

Package

Name
apache-airflow-providers-yandex
View open source insights on deps.dev
Purl
pkg:pypi/apache-airflow-providers-yandex

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.5.1

Affected versions

1.*
1.0.0b1
1.0.0b2
1.0.0rc1
1.0.0
1.0.1rc1
1.0.1
2.*
2.0.0rc1
2.0.0rc2
2.0.0
2.1.0rc1
2.1.0
2.2.0rc1
2.2.0
2.2.1rc1
2.2.1
2.2.2rc1
2.2.2
2.2.3rc1
2.2.3
3.*
3.0.0rc1
3.0.0rc2
3.0.0
3.1.0rc1
3.1.0rc2
3.1.0rc3
3.1.0
3.2.0rc1
3.2.0rc2
3.2.0rc3
3.2.0
3.3.0rc1
3.3.0
3.4.0rc1
3.4.0
3.5.0rc1
3.5.0
3.6.0rc1
3.6.0
3.7.0rc1
3.7.0
3.7.1rc1
3.7.1
3.8.0rc1
3.8.0rc2
3.8.0
3.9.0rc1
3.9.0
3.9.1rc1
3.10.0rc2
3.10.0
3.11.0rc1
3.11.0
3.11.1rc1
3.11.1
3.11.2rc1
3.11.2
3.12.0rc1
3.12.0
4.*
4.0.0rc1
4.0.0rc2
4.0.0
4.0.1rc1
4.0.1
4.0.2rc1
4.0.2
4.0.3rc1
4.0.3
4.1.0rc1
4.1.0
4.1.1rc1
4.1.1
4.2.0rc1
4.2.0
4.2.1rc1
4.2.1
4.3.0rc1
4.3.0
4.3.1rc1
4.3.1
4.3.2rc1
4.3.2
4.3.3rc1
4.3.3
4.4.0rc1
4.4.0
4.4.1rc1
4.4.1
4.4.2rc1
4.4.2
4.5.0rc1
4.5.0
4.5.1rc1
4.5.1rc2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-qmrf-jrpr-rjx6/GHSA-qmrf-jrpr-rjx6.json"