Impact
The vulnerability lies in the Admin password‑edit PATCH endpoint of the Apache Airflow FAB provider, where changing a user’s password does not invalidate existing database‑backed sessions tied to that user. Because session cookies remain valid, any entity that already possesses a victim’s session cookie can continue to act with the victim’s credentials even after the password change. This flaw represents an improper session validation weakness (CWE‑613) and undermines the security guarantee that a password change revokes all active sessions.
Affected Systems
Impact is limited to deployments using the FAB authentication manager with database‑backed sessions. The flaw applies to all versions of apache-airflow-providers-fab prior to the release of version 3.9.0; the patch introduces session‑invalidation during password changes.
Risk and Exploitability
The vulnerability can be exploited only if an attacker already has a session cookie for the target. Because the EPSS score is < 1% and the CVSS score is 9.1, and the flaw is not listed in CISA’s KEV catalog, the exploitation that an attacker who already hijacked a session can persist indefinitely indicates a high potential impact. The network attack vector is indirect, depending on prior session compromise.
OpenCVE Enrichment