Impact
Apache Airflow’s Teradata provider can embed cloud storage credentials directly into SQL statements when using S3ToTeradataOperator or AzureBlobStorageToTeradataOperator. This flaw causes credentials to appear in the task log and, more critically, in Teradata’s DBQL query logs and monitoring views. As a result, any user with access to Airflow logs or Teradata monitoring can obtain the credentials, leading to unauthorized access to cloud storage buckets or containers.
Affected Systems
The vulnerability affects deployments of Apache Airflow using the Teradata provider where the operator is configured to transfer data to a private Teradata table and the supplier does not supply a teradata_authorization_name. Specifically, it applies to the S3ToTeradataOperator and AzureBlobStorageToTeradataOperator in versions prior to the 3.7.0 upgrade of apache-airflow-providers-teradata.
Risk and Exploitability
The flaw is identified as CWE‑532 (Information Exposure Through Log Files). No CVSS score is available, but the lack of necessary credentials in an authorization object and the default inline embedding pattern suggest a high potential impact. The EPSS score is not available, making it difficult to gauge current exploitation likelihood, yet the exposure of sensitive credentials typically carries substantial risk. The problem is not currently listed in the CISA KEV catalog, but it remains a critical concern due to the clear path for credential leakage.
OpenCVE Enrichment