Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a malicious airflow user on site A where they log in normally, to access unauthorized Airflow Webserver on Site B through the session from Site A. This does not affect users who have changed the default value for `[webserver] secret_key` config.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2020-12-21T16:45:13
Updated: 2024-08-04T14:00:47.524Z
Reserved: 2020-08-12T00:00:00
Link: CVE-2020-17526
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-12-21T17:15:12.507
Modified: 2024-11-21T05:08:17.777
Link: CVE-2020-17526
Redhat
No data.