apache-airflow-providers-celery@1.0.1 vulnerabilities

Provider package apache-airflow-providers-celery for Apache Airflow

Direct Vulnerabilities

Known vulnerabilities in the apache-airflow-providers-celery package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Insertion of Sensitive Information into Log File

apache-airflow-providers-celery is a Provider for Apache Airflow. Implements apache-airflow-providers-celery package

Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File when the Celery result backend is used with rediss, amqp, or rpc protocols. An attacker can view sensitive information in clear text by accessing the logs.

Note: This is only exploitable if the logs are accessible to the attacker.

How to fix Insertion of Sensitive Information into Log File?

Upgrade apache-airflow-providers-celery to version 3.4.1 or higher.

[,3.4.1)