In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-0009 In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.
Github GHSA Github GHSA GHSA-5ff8-7639-6v6g Apache Airflow Session Fixation vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-03T10:45:51.955Z

Reserved: 2022-08-09T00:00:00

Link: CVE-2022-38054

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-09-02T07:15:07.777

Modified: 2024-11-21T07:15:39.843

Link: CVE-2022-38054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses