Apache

Apache-airflow-providers-fab

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.68%
  • Veröffentlicht 29.07.2026 08:35:37
  • Zuletzt bearbeitet 05.08.2026 18:37:13

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an ar...

  • EPSS 0.36%
  • Veröffentlicht 13.07.2026 15:05:21
  • Zuletzt bearbeitet 14.07.2026 14:16:36

In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the globa...

  • EPSS 0.58%
  • Veröffentlicht 25.05.2026 10:41:16
  • Zuletzt bearbeitet 23.07.2026 17:10:00

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate...

  • EPSS 0.95%
  • Veröffentlicht 08.01.2025 09:15:07
  • Zuletzt bearbeitet 03.06.2025 21:11:55

Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed with admin CLI, the sessions for that user have not been cleared, leadin...

  • EPSS 0.93%
  • Veröffentlicht 05.08.2024 08:15:56
  • Zuletzt bearbeitet 19.03.2025 15:15:49

Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache Airflow Providers FAB: 1.2.1 (when used with Apache Airflow 2.9.3) and FAB 1.2.0 for all Airflow versions. The FAB provider prevented the user f...