Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a …
提示
摘要
Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator that causes the backend to resolve a secret belonging to a different team, because the lookup path is concatenated from an unvalidated key after the team-scoped lookup misses. The Execution API Variables route accepts a path-shaped key, so this is reachable f…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://github.com/apache/airflow/pull/72646
- https://lists.apache.org/thread/vczt5xgqjv8ot8fpp1vdq3rmnfm50w0g
- https://www.cve.org/CVERecord?id=CVE-2026-68870
- https://www.cve.org/CVERecord?id=CVE-2026-68871
- https://www.cve.org/CVERecord?id=CVE-2026-68872
时间线
- nvd_ingest NVD