In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2022-0018 | In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API. |
![]() |
GHSA-3q8r-f3pj-3gc4 | Apache Airflow may allow authenticated users who have been deactivated to continue using the UI or API |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-03T12:49:43.427Z
Reserved: 2022-09-27T00:00:00
Link: CVE-2022-41672

No data.

Status : Modified
Published: 2022-10-07T07:15:08.897
Modified: 2024-11-21T07:23:36.813
Link: CVE-2022-41672

No data.

No data.