PT-2026-102497 · Apache Airflow · Apache Airflow Teradata Provider
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
apache-airflow-providers-teradata versions prior to 3.7.0
Description
The Teradata provider in Apache Airflow embeds cloud storage credentials directly into SQL statements as plain string literals within the
CREATE MULTISET TABLE ... LOCATION statement. This occurs when using S3ToTeradataOperator or AzureBlobStorageToTeradataOperator with a private bucket and no teradata authorization name configured. Consequently, credentials are exposed in two locations: the Airflow task logs and Teradata's DBQL query logs and live monitoring views. Specifically, S3ToTeradataOperator may expose runtime AWS credentials and STS session tokens in Airflow logs, while AzureBlobStorageToTeradataOperator exposes storage account keys within Teradata's internal logs.Recommendations
Upgrade to apache-airflow-providers-teradata version 3.7.0 or later.
Configure
teradata authorization name with a Teradata AUTHORIZATION object to prevent credentials from being inlined.
Rotate any credentials previously used through the inline path.Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow Teradata Provider