Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
Moderate severity
GitHub Reviewed
Published
May 19, 2026
to the GitHub Advisory Database
•
Updated Jun 5, 2026
Description
Published by the National Vulnerability Database
May 19, 2026
Published to the GitHub Advisory Database
May 19, 2026
Reviewed
Jun 5, 2026
Last updated
Jun 5, 2026
In the AWS Secrets Manager and SSM Parameter Store secrets backends of
apache-airflow-providers-amazonprior to 9.28.0, the team-scoping logic could resolve aconn_idcontaining a/(e.g."my_team/conn") to the same path as another team's team-scoped secret when the caller had no team context. A privileged caller without team context could therefore retrieve another team's secret by crafting a collidingconn_id. Fixed in 9.28.0 by switching the team-scope separator to--and rejecting team-shapedconn_ids when team context is absent. Affects the experimental multi-tenant teams feature only. Users are recommended to upgrade toapache-airflow-providers-amazon9.28.0, which fixes the issue.References