azure-databricks-sql-statement-results

SQL query result rows can contain arbitrary customer data and stored credentials.

azurecritical service: azure:databricks emits CanReadData

Where it sits

locationDatabricks SQL Statement Execution result.data_array
location kinddata_record
data kindscredential password api_key access_key secret_key oauth_token connection_string sensitive_data pii customer_data
emits edgeCanReadData
serviceAzure Databricks (azure:databricks)

Collection recipe

access modedata_plane
operationGET /api/2.0/sql/statements/{statement_id}
response pathresult.data_array
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

CAN_USE
SELECT

References

move · open · esc close